You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa Xerces-C

Sigurnosni nedostatak programskog paketa Xerces-C

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256

=====================================================================
Red Hat Security Advisory

Synopsis: Important: xerces-c security update
Advisory ID: RHSA-2020:0702-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2020:0702
Issue date: 2020-03-04
CVE Names: CVE-2018-1311
=====================================================================

1. Summary:

An update for xerces-c is now available for Red Hat Enterprise Linux 6.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux Desktop Optional (v. 6) – i386, noarch, x86_64
Red Hat Enterprise Linux HPC Node Optional (v. 6) – noarch, x86_64
Red Hat Enterprise Linux Server Optional (v. 6) – i386, noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 6) – i386, noarch, x86_64

3. Description:

Xerces-C is a validating XML parser written in a portable subset of C++.
Xerces-C makes it easy to give your application the ability to read and
write XML data. A shared library is provided for parsing, generating,
manipulating, and validating XML documents.

Security Fix(es):

* xerces-c: XML parser contains a use-after-free error triggered during the
scanning of external DTDs (CVE-2018-1311)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1788472 – CVE-2018-1311 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs

6. Package List:

Red Hat Enterprise Linux Desktop Optional (v. 6):

Source:
xerces-c-3.0.1-21.el6_10.src.rpm

i386:
xerces-c-3.0.1-21.el6_10.i686.rpm
xerces-c-debuginfo-3.0.1-21.el6_10.i686.rpm
xerces-c-devel-3.0.1-21.el6_10.i686.rpm

noarch:
xerces-c-doc-3.0.1-21.el6_10.noarch.rpm

x86_64:
xerces-c-3.0.1-21.el6_10.i686.rpm
xerces-c-3.0.1-21.el6_10.x86_64.rpm
xerces-c-debuginfo-3.0.1-21.el6_10.i686.rpm
xerces-c-debuginfo-3.0.1-21.el6_10.x86_64.rpm
xerces-c-devel-3.0.1-21.el6_10.i686.rpm
xerces-c-devel-3.0.1-21.el6_10.x86_64.rpm

Red Hat Enterprise Linux HPC Node Optional (v. 6):

Source:
xerces-c-3.0.1-21.el6_10.src.rpm

noarch:
xerces-c-doc-3.0.1-21.el6_10.noarch.rpm

x86_64:
xerces-c-3.0.1-21.el6_10.i686.rpm
xerces-c-3.0.1-21.el6_10.x86_64.rpm
xerces-c-debuginfo-3.0.1-21.el6_10.i686.rpm
xerces-c-debuginfo-3.0.1-21.el6_10.x86_64.rpm
xerces-c-devel-3.0.1-21.el6_10.i686.rpm
xerces-c-devel-3.0.1-21.el6_10.x86_64.rpm

Red Hat Enterprise Linux Server Optional (v. 6):

Source:
xerces-c-3.0.1-21.el6_10.src.rpm

i386:
xerces-c-3.0.1-21.el6_10.i686.rpm
xerces-c-debuginfo-3.0.1-21.el6_10.i686.rpm
xerces-c-devel-3.0.1-21.el6_10.i686.rpm

noarch:
xerces-c-doc-3.0.1-21.el6_10.noarch.rpm

x86_64:
xerces-c-3.0.1-21.el6_10.i686.rpm
xerces-c-3.0.1-21.el6_10.x86_64.rpm
xerces-c-debuginfo-3.0.1-21.el6_10.i686.rpm
xerces-c-debuginfo-3.0.1-21.el6_10.x86_64.rpm
xerces-c-devel-3.0.1-21.el6_10.i686.rpm
xerces-c-devel-3.0.1-21.el6_10.x86_64.rpm

Red Hat Enterprise Linux Workstation Optional (v. 6):

Source:
xerces-c-3.0.1-21.el6_10.src.rpm

i386:
xerces-c-3.0.1-21.el6_10.i686.rpm
xerces-c-debuginfo-3.0.1-21.el6_10.i686.rpm
xerces-c-devel-3.0.1-21.el6_10.i686.rpm

noarch:
xerces-c-doc-3.0.1-21.el6_10.noarch.rpm

x86_64:
xerces-c-3.0.1-21.el6_10.i686.rpm
xerces-c-3.0.1-21.el6_10.x86_64.rpm
xerces-c-debuginfo-3.0.1-21.el6_10.i686.rpm
xerces-c-debuginfo-3.0.1-21.el6_10.x86_64.rpm
xerces-c-devel-3.0.1-21.el6_10.i686.rpm
xerces-c-devel-3.0.1-21.el6_10.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2018-1311
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIVAwUBXl+eX9zjgjWX9erEAQhc3hAAnpm3fkDi1TAT8YXqPHGswyUOVI78CnvX
uNzCYJ9SiYGGHnXe8O9kOd/RzZHCBEqcgMmBNd3Tf49vGw6xZux7bOr13F/0bApU
ahlWGi+eHtGMM3DpCBnXah1CSeEVuP5MqDY6KHnkg+yTfwKig6S6hsoWD5v6YiLp
48TnqMmQHq/1W5FYEyA1dQNHYczkYjbQZDShn/YNS+JKe80W1PETBqn8MKaeKjYF
EDXohdCn1vyVOBamXC65hRZUUHWmjr2mmOVTULLXH2A6SIzaojrPmoZMeaJ1gj+H
nkfOqgvvLgBJXUPuBUeeO7qVbOdH6dDw8KT0D2y1i3A+L4E4cOUuUX4JQC5voS/k
KjH3bC7XP5xA8YDPF9+0f7nr9MYjHMtH+5kqLcuLP+OKj70hl0mLSGuibUt6ojYD
QxmYCTMyP67U1tDYuPTwDtorVKo07FtriRSuWkIeACvEvP7WdtcNCYzmeKrTE+Ez
1S1Rpn70kJLax0ULby2QK0RHql6KUvMDsU+YA1bsa1X2goeQIJAiP40VVgJ+MKxG
ljlQVZWXc0AXj7FtMzx23jK9udC7G0zFLm4VMwY5IUXyyOBH5RBoBfmZzQ7XwmF7
3u6vFhTTuWrOejHsppWmMYQC7XGjLqxP7L6LmQ7p2anvht5r39avA11dk0+rRXL7
lXuNyD5z6gY=
=QXpj
—–END PGP SIGNATURE—–


RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256

=====================================================================
Red Hat Security Advisory

Synopsis: Important: xerces-c security update
Advisory ID: RHSA-2020:0704-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2020:0704
Issue date: 2020-03-04
CVE Names: CVE-2018-1311
=====================================================================

1. Summary:

An update for xerces-c is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux Client Optional (v. 7) – noarch, x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) – noarch, x86_64
Red Hat Enterprise Linux Server (v. 7) – ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) – noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Workstation (v. 7) – x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) – noarch, x86_64

3. Description:

Xerces-C is a validating XML parser written in a portable subset of C++.
Xerces-C makes it easy to give your application the ability to read and
write XML data. A shared library is provided for parsing, generating,
manipulating, and validating XML documents.

Security Fix(es):

* xerces-c: XML parser contains a use-after-free error triggered during the
scanning of external DTDs (CVE-2018-1311)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1788472 – CVE-2018-1311 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs

6. Package List:

Red Hat Enterprise Linux Client Optional (v. 7):

Source:
xerces-c-3.1.1-10.el7_7.src.rpm

noarch:
xerces-c-doc-3.1.1-10.el7_7.noarch.rpm

x86_64:
xerces-c-3.1.1-10.el7_7.i686.rpm
xerces-c-3.1.1-10.el7_7.x86_64.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.i686.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.x86_64.rpm
xerces-c-devel-3.1.1-10.el7_7.i686.rpm
xerces-c-devel-3.1.1-10.el7_7.x86_64.rpm

Red Hat Enterprise Linux ComputeNode Optional (v. 7):

Source:
xerces-c-3.1.1-10.el7_7.src.rpm

noarch:
xerces-c-doc-3.1.1-10.el7_7.noarch.rpm

x86_64:
xerces-c-3.1.1-10.el7_7.x86_64.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.i686.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.x86_64.rpm
xerces-c-devel-3.1.1-10.el7_7.i686.rpm
xerces-c-devel-3.1.1-10.el7_7.x86_64.rpm

Red Hat Enterprise Linux Server (v. 7):

Source:
xerces-c-3.1.1-10.el7_7.src.rpm

ppc64:
xerces-c-3.1.1-10.el7_7.ppc.rpm
xerces-c-3.1.1-10.el7_7.ppc64.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.ppc.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.ppc64.rpm

ppc64le:
xerces-c-3.1.1-10.el7_7.ppc64le.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.ppc64le.rpm

s390x:
xerces-c-3.1.1-10.el7_7.s390.rpm
xerces-c-3.1.1-10.el7_7.s390x.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.s390.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.s390x.rpm

x86_64:
xerces-c-3.1.1-10.el7_7.i686.rpm
xerces-c-3.1.1-10.el7_7.x86_64.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.i686.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.x86_64.rpm

Red Hat Enterprise Linux Server Optional (v. 7):

noarch:
xerces-c-doc-3.1.1-10.el7_7.noarch.rpm

ppc64:
xerces-c-debuginfo-3.1.1-10.el7_7.ppc.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.ppc64.rpm
xerces-c-devel-3.1.1-10.el7_7.ppc.rpm
xerces-c-devel-3.1.1-10.el7_7.ppc64.rpm

ppc64le:
xerces-c-debuginfo-3.1.1-10.el7_7.ppc64le.rpm
xerces-c-devel-3.1.1-10.el7_7.ppc64le.rpm

s390x:
xerces-c-debuginfo-3.1.1-10.el7_7.s390.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.s390x.rpm
xerces-c-devel-3.1.1-10.el7_7.s390.rpm
xerces-c-devel-3.1.1-10.el7_7.s390x.rpm

x86_64:
xerces-c-debuginfo-3.1.1-10.el7_7.i686.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.x86_64.rpm
xerces-c-devel-3.1.1-10.el7_7.i686.rpm
xerces-c-devel-3.1.1-10.el7_7.x86_64.rpm

Red Hat Enterprise Linux Workstation (v. 7):

Source:
xerces-c-3.1.1-10.el7_7.src.rpm

x86_64:
xerces-c-3.1.1-10.el7_7.i686.rpm
xerces-c-3.1.1-10.el7_7.x86_64.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.i686.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.x86_64.rpm

Red Hat Enterprise Linux Workstation Optional (v. 7):

noarch:
xerces-c-doc-3.1.1-10.el7_7.noarch.rpm

x86_64:
xerces-c-debuginfo-3.1.1-10.el7_7.i686.rpm
xerces-c-debuginfo-3.1.1-10.el7_7.x86_64.rpm
xerces-c-devel-3.1.1-10.el7_7.i686.rpm
xerces-c-devel-3.1.1-10.el7_7.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2018-1311
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2020 Red Hat, Inc.
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIVAwUBXl/GNtzjgjWX9erEAQhVOA/8D1+BdvxOVP3Og+AbYov7hEMp/VJGOuDi
1eMjld1R9X0Fz/BeBT86VuVXDogwdQkbcOHrXkLBExoJ58o5oXCG3dSluvp++IHO
+YC1NNspApANitM+mzG2pIPIQUQnfIbsGEJaUU5rCa/mAZXEQZzyuZQLGAfSEO5T
4tOClknmslZdo3HppVmpDA4eNPnPAvmaqO0GT1hQblWTzHcas1DOZLgKgAEjpI/x
KDRmZ56zBb+jDjoo27TeUMj5ydKzNARC4vLAH93aKQFVbWqqa0uheXLfh40UuFYQ
NeklTkb6F/LrArNqc2+XKHdv0NmdJccJiqAkG9zv31A7ZS3nkChc2EXgUfV8ReG6
I38ED2JDAAdftO3+/DCORRzQRk9LgiKCLEaZ9iUyI5V+YELyGT0IrRFcGameZ55w
of4ODghIMC1slo7QDr11oGvUsk7pP87oQKuuPv2Oll0eaB3lCQZqQAzH0FxuWnJw
V9QOJyKnKZ4ftl6k1N4lcp9Q3NeagmPiLxZ/vZJ1goZfRVs/lDN7TRlWM/ic0iUA
Tziffre8LrTzFwzT3Pu6v7VOnlPL3Y3/XzZ8Ctln9e/p3ADPyUFX1TKB3OpuGkY1
j6aGHiDJ5FxX80sGvyXToHvJE1XshqLiZoftFpF0y8OZpzHOpCsUuHDWkvIn5CtP
+xNUYV8EK7k=
=XVWQ
—–END PGP SIGNATURE—–


RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

Top
More in Preporuke
Sigurnosni nedostaci jezgre operacijskog sustava

Otkriveni su sigurnosni nedostaci jezgre operacijskog sustava RHEL. Otkriveni nedostaci potencijalnim udaljenim napadačima omogućuju izazivanje DoS stanja ili izvršavanje proizvoljnog...

Close