Candidate: CVE-2016-0729 PublicDate: 2016-04-07 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0729 https://marc.info/?l=oss-security&m=145641008814590&w=2 http://xerces.apache.org/xerces-c/secadv/CVE-2016-0729.txt http://svn.apache.org/viewvc?view=revision&revision=1727978 Description: Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corruption) or possibly execute arbitrary code via a crafted document. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=815907 Priority: medium Discovered-by: Gustavo Grieco Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_xerces-c: upstream: http://svn.apache.org/viewvc?view=revision&revision=1727978 upstream_xerces-c: released (V3.1.3) precise_xerces-c: released (3.1.1-1+deb6u2build0.12.04.1) precise/esm_xerces-c: DNE (precise was released [3.1.1-1+deb6u2build0.12.04.1]) trusty_xerces-c: released (3.1.1-5.1+deb8u1build0.14.04.1) trusty/esm_xerces-c: released (3.1.1-5.1+deb8u1build0.14.04.1) vivid/stable-phone-overlay_xerces-c: DNE vivid/ubuntu-core_xerces-c: DNE wily_xerces-c: released (3.1.1-5.1+deb8u1build0.15.10.1) xenial_xerces-c: not-affected (3.1.3+debian-1) yakkety_xerces-c: ignored (reached end-of-life) zesty_xerces-c: ignored (reached end-of-life) artful_xerces-c: ignored (reached end-of-life) bionic_xerces-c: not-affected (3.1.3+debian-1) cosmic_xerces-c: not-affected (3.1.3+debian-1) devel_xerces-c: not-affected (3.1.3+debian-1)