Debian DSA-4265-1 : xml-security-c - security update

High Nessus Plugin ID 111538


The remote Debian host is missing a security-related update.


It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer dereferences when processing malformed XML data.


Upgrade the xml-security-c packages.

For the stable distribution (stretch), this problem has been fixed in version 1.7.3-4+deb9u1.

See Also

Plugin Details

Severity: High

ID: 111538

File Name: debian_DSA-4265.nasl

Version: 1.3

Type: local

Agent: unix

Published: 2018/08/06

Updated: 2018/11/13

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:xml-security-c, cpe:/o:debian:debian_linux:9.0

Patch Publication Date: 2018/08/05

Reference Information

DSA: 4265