• [SECURITY] [DSA 4407-1] xmltooling security update

    From Moritz Muehlenhoff@1:229/2 to All on Tue Mar 12 22:40:02 2019
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4407-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff
    March 12, 2019 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : xmltooling
    CVE ID : CVE-2019-9628

    Ross Geerlings discovered that the XMLTooling library didn't correctly
    handle exceptions on malformed XML declarations, which could result in
    denial of service against the application using XMLTooling.

    For the stable distribution (stretch), this problem has been fixed in
    version 1.6.0-4+deb9u2.

    We recommend that you upgrade your xmltooling packages.

    For the detailed security status of xmltooling please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/xmltooling

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlyII8sACgkQEMKTtsN8 TjaCAg/+NuYO7gqcYZ0ji1AXLo3hYJ0QXqxHaDXQ9wBRziO7m8sd47+3KGYUevEQ UV/QZ3u2siqwb9URPtWhKGLHeAVzBKdhF+vFBMQquG+7Zp43vuLOpQyYWT8799Gp 6mH1RZYSMofNGY5Lv6FecmAL0IBteFCFH2DRTEvXEUX+0GbM8/KKtPvXL8Z0PV6u Z9g16+ygB7JdRW7tzf4nJ10KSFSVTG7NIhh/CqfbNJbFkI/wlsEVjyVIjob5abc8 VI9faNBGlA3CmKtdKXGKmoKFJxzDVDq7uLoGzippH97RSyhaaQ/xXpJUsuHV0y9P pNLRRRzQEd4SqQF2PF9F5Pe+TIxHHeuDU33DpGHUU5IaKYDBs+bAJyw/zT9FVhg+ wv6rVo6DgvX8UDrK7P8f+SPvtEvA+oC5uORguqKO5Ir6OLs2O2XgGO8D4vI5Een5 V3pz+NLEpPMRXHBLLGnkeliYqgKAwq0AvKvnUgyjIVjQ7XxFgG3/DEJMiU4o8GM4 4IhCzPtIVqLsJJ8eM8RXvMEhHytBGXclwdfsoano0VMI5kESJ1HuWpTOcNGVGQaD dX3hejMcZsbors3JTwVKMbRx/l0rjhAu2SAOsMFdVszj0+A/bi/sHGP7/6k88Nmt +tZ+2Kv/GmM9bwDLLiEJ8N7HUgNbmdzaa3b7R6obKZs7ORb8azY=
    =JlOC
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)