Xerces-C++: Multiple vulnerabilities Multiple vulnerabilities have been found in Xerces-C++, the worst of which may allow remote attackers to execute arbitrary code. xerces-c 2016-12-24 2016-12-24 575700 584506 local, remote 3.1.4-r1 3.1.4-r1

Xerces-C++ is a validating XML parser written in a portable subset of C++.

Multiple vulnerabilities have been discovered in Xerces-C++. Please review the CVE identifiers referenced below for details.

A remote attacker could entice a user to process a specially crafted file, possibly resulting in the remote execution of arbitrary code with the privileges of the process, or a Denial of Service condition.

There is no known workaround at this time.

All Xerces-C++ users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/xerces-c-3.1.4-r1"
CVE-2016-0729 CVE-2016-2099 b-man whissi