First published: Thu Apr 07 2016(Updated: )
Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corruption) or possibly execute arbitrary code via a crafted document.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Samsung X14J eu | =t-ms14jakucb-1102.5 | |
Fedoraproject Fedora | =22 | |
Fedoraproject Fedora | =23 | |
Fedoraproject Fedora | =24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0729 has a high severity due to the potential for remote code execution and denial of service.
To fix CVE-2016-0729, update the Apache Xerces-C library to version 3.1.3 or later.
CVE-2016-0729 affects multiple versions of Fedora (22, 23, and 24) and the Samsung X14J firmware.
CVE-2016-0729 involves multiple buffer overflow vulnerabilities in the XML Parser library of Apache Xerces-C.
Yes, CVE-2016-0729 can potentially lead to unauthorized access and data breaches through remote code execution.