[GitHub] [xerces-c] rouault opened a new pull request #4 7: [XERCESC-2188] Fix potential double-free in usage of Rea derMgr::pushReader()

GitBox <[email protected]>
Newsgroups gmane.text.xml.xerces-c.devel
Message-ID <[email protected]>
rouault opened a new pull request #47:
URL: https://github.com/apache/xerces-c/pull/47


   The fix consists in adding a new argument to pushReader() to specify if
   ReaderMgr must own the passed entity, and adapt callers to specify the
   right value of this ownership flag depending on the calling context.
   
   SPDX-FileCopyrightText: Portions Copyright 2021 Siemens
   Modified on 15-Jul-2021 by Siemens and/or its affiliates to fix CVE-2018-1311: Apache Xerces-C use-after-free vulnerability scanning external DTD. Copyright 2021 Siemens.
   
   Co-authored-by: Even Rouault <[email protected]>
   
   Supersedes https://github.com/apache/xerces-c/pull/46 (avoids the memory leak in the unit tests)
   @johnjamesmccann  Do you have access to a reproducer to confirm it fixes the issue ? I couldn't easily find a reproducer 


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.