USN-3921-1: XMLTooling Vulnerability | Ubuntu Security Notices

Your submission was sent successfully! Close

Thank you for contacting us. A member of our team will be in touch shortly. Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter! In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Your preferences have been successfully updated. Close notification

Please try again or file a bug report. Close

Security
  • Platform Security
  • ESM
  • Livepatch
  • Security standards
  • CVEs
  • Notices
  • Assurances
  1. Ubuntu Security Notices
  2. USN-3921-1
USN-3921-1: XMLTooling vulnerability

Publication date

26 March 2019

Overview

xmltooling could be made to crash if it opened a specially crafted file.

Releases

18.10 18.04 LTS 16.04 LTS 14.04 LTS Open side navigation Close side navigation
  • Packages
  • Details
  • Update instructions
  • References

Packages

  • xmltooling - C++ XML parsing library with encryption support

Details

It was discovered that XMLTooling incorrectly handled certain XML files with invalid data. An attacker could use this issue to cause XMLTooling to crash, resulting in a denial of service.

It was discovered that XMLTooling incorrectly handled certain XML files with invalid data. An attacker could use this issue to cause XMLTooling to crash, resulting in a denial of service.

Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
18.10 cosmic libxmltooling8 – 3.0.2-1ubuntu1.1
18.04 LTS bionic libxmltooling7 – 1.6.4-1ubuntu2.1
16.04 LTS xenial libxmltooling6v5 – 1.5.6-2ubuntu0.3
14.04 LTS trusty libxmltooling6 – 1.5.3-2+deb8u3ubuntu0.1

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.

Get Ubuntu Pro

References

  • CVE-2019-9628
  • CVE-2019-9628

Have additional questions?

Talk to a member of the team ›

Từ khóa » Cn 3921