{"id":"openSUSE-SU-2019:1283-1","summary":"Security update for xerces-c","details":"This update for xerces-c fixes the following issue:\n\n- CVE-2017-12627: Processing of external DTD paths could have resulted in a\n  null pointer dereference under certain conditions (bsc#1083630)\n\nThis update was imported from the SUSE:SLE-15:Update update project.","modified":"2026-03-11T07:32:05.512325Z","published":"2019-04-26T15:51:12Z","related":["CVE-2017-12627"],"upstream":["CVE-2017-12627"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GX7LPYGMLCK5RZCA7GR57FT37ALMTPZL/#GX7LPYGMLCK5RZCA7GR57FT37ALMTPZL"},{"type":"REPORT","url":"https://bugzilla.suse.com/1083630"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-12627"}],"affected":[{"package":{"name":"xerces-c","ecosystem":"openSUSE:Leap 15.0","purl":"pkg:rpm/opensuse/xerces-c&distro=openSUSE%20Leap%2015.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.4-lp150.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"libxerces-c-3_1-32bit":"3.1.4-lp150.2.3.1","libxerces-c-3_1":"3.1.4-lp150.2.3.1","libxerces-c-devel":"3.1.4-lp150.2.3.1","xerces-c-doc":"3.1.4-lp150.2.3.1","xerces-c":"3.1.4-lp150.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:1283-1.json"}}],"schema_version":"1.7.5"}