-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4407-1 security@xxxxxxxxxx https://www.debian.org/security/ Moritz Muehlenhoff March 12, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : xmltooling CVE ID : CVE-2019-9628 Ross Geerlings discovered that the XMLTooling library didn't correctly handle exceptions on malformed XML declarations, which could result in denial of service against the application using XMLTooling. For the stable distribution (stretch), this problem has been fixed in version 1.6.0-4+deb9u2. We recommend that you upgrade your xmltooling packages. For the detailed security status of xmltooling please refer to its security tracker page at: https://security-tracker.debian.org/tracker/xmltooling Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@xxxxxxxxxxxxxxxx -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlyII8sACgkQEMKTtsN8 TjaCAg/+NuYO7gqcYZ0ji1AXLo3hYJ0QXqxHaDXQ9wBRziO7m8sd47+3KGYUevEQ UV/QZ3u2siqwb9URPtWhKGLHeAVzBKdhF+vFBMQquG+7Zp43vuLOpQyYWT8799Gp 6mH1RZYSMofNGY5Lv6FecmAL0IBteFCFH2DRTEvXEUX+0GbM8/KKtPvXL8Z0PV6u Z9g16+ygB7JdRW7tzf4nJ10KSFSVTG7NIhh/CqfbNJbFkI/wlsEVjyVIjob5abc8 VI9faNBGlA3CmKtdKXGKmoKFJxzDVDq7uLoGzippH97RSyhaaQ/xXpJUsuHV0y9P pNLRRRzQEd4SqQF2PF9F5Pe+TIxHHeuDU33DpGHUU5IaKYDBs+bAJyw/zT9FVhg+ wv6rVo6DgvX8UDrK7P8f+SPvtEvA+oC5uORguqKO5Ir6OLs2O2XgGO8D4vI5Een5 V3pz+NLEpPMRXHBLLGnkeliYqgKAwq0AvKvnUgyjIVjQ7XxFgG3/DEJMiU4o8GM4 4IhCzPtIVqLsJJ8eM8RXvMEhHytBGXclwdfsoano0VMI5kESJ1HuWpTOcNGVGQaD dX3hejMcZsbors3JTwVKMbRx/l0rjhAu2SAOsMFdVszj0+A/bi/sHGP7/6k88Nmt +tZ+2Kv/GmM9bwDLLiEJ8N7HUgNbmdzaa3b7R6obKZs7ORb8azY= =JlOC -----END PGP SIGNATURE-----