CVE-2016-0729: Apache Xerces-C XML Parser Crashes on Malformed Input
Wessel, Keith
kwessel at illinois.edu
Mon Mar 14 17:45:31 EDT 2016
Thanks, Scott.
Keith
-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Monday, March 14, 2016 4:34 PM
To: Shib Users <users at shibboleth.net>
Subject: RE: CVE-2016-0729: Apache Xerces-C XML Parser Crashes on Malformed Input
> Am I correct that an unpatched system is susceptible to a remote code
> execution, or is it just a service crash?
If you ask me, the answer is I don't know and I assume the worst. If you ask Red Hat, the advisory they issued says they think it's just a crash. You would have to ask them why they concluded that, but the CVE text I provided was consistent in referring to it as a potential remote code execution vulnerability.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
More information about the users
mailing list