Bug#540297: CVE-2009-1885: DoS vulnerability (by simply nested DTD structures)

2009-08-19 Thread Jay Berkenbilt
Daniel Leidert wrote: > Package: xerces-c > Severity: important > Tags: patch > > > It seems, there is a DoS vulnerability in xerces-c (very probably in the > 2.x version too): > > http://svn.apache.org/viewvc?view=rev&revision=781488 > http://www.cert.fi/en/reports/2009/vulnerability2009085.html

Bug#540297: CVE-2009-1885: DoS vulnerability (by simply nested DTD structures)

2009-08-06 Thread Daniel Leidert
Package: xerces-c Severity: important Tags: patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 It seems, there is a DoS vulnerability in xerces-c (very probably in the 2.x version too): http://svn.apache.org/viewvc?view=rev&revision=781488 http://www.cert.fi/en/reports/2009/vulnerability2009085