ALAS2-2018-1124

Related Vulnerabilities: CVE-2016-4463  

A stack exhaustion flaw was found in the way Xerces-C XML parser handled deeply nested DTDs. An attacker could potentially use this flaw to crash an application using Xerces-C by tricking it into processing specially crafted data.(CVE-2016-4463)

ALAS2-2018-1124


Amazon Linux 2 Security Advisory: ALAS-2018-1124
Advisory Release Date: 2018-12-06 20:30 Pacific
Advisory Updated Date: 2018-12-08 01:51 Pacific
Severity: Medium
References: CVE-2016-4463 

Issue Overview:

A stack exhaustion flaw was found in the way Xerces-C XML parser handled deeply nested DTDs. An attacker could potentially use this flaw to crash an application using Xerces-C by tricking it into processing specially crafted data.(CVE-2016-4463)


Affected Packages:

xerces-c


Issue Correction:
Run yum update xerces-c to update your system.

New Packages:
aarch64:
    xerces-c-3.1.1-9.amzn2.aarch64
    xerces-c-devel-3.1.1-9.amzn2.aarch64
    xerces-c-debuginfo-3.1.1-9.amzn2.aarch64

i686:
    xerces-c-3.1.1-9.amzn2.i686
    xerces-c-devel-3.1.1-9.amzn2.i686
    xerces-c-debuginfo-3.1.1-9.amzn2.i686

noarch:
    xerces-c-doc-3.1.1-9.amzn2.noarch

src:
    xerces-c-3.1.1-9.amzn2.src

x86_64:
    xerces-c-3.1.1-9.amzn2.x86_64
    xerces-c-devel-3.1.1-9.amzn2.x86_64
    xerces-c-debuginfo-3.1.1-9.amzn2.x86_64