http://xml.apache.org/http://www.apache.org/http://www.w3.org/

Xerces Project

Overview
Charter
Release Info
Security
Download

Xerces-C++ 3.3.0
Installation
Build Instructions

Programming
Samples
FAQs

API Reference
DOM C++ Binding
Migration Guide

Feedback
Bug-Reporting
Mailing Lists

Source Repository
Applications

Security Model
 

Apache Xerces-C++ currently lacks active maintainers and therefore needs to tightly scope what security guarantees it provides.

We recommend that users that process untrusted input take their own precautions to make sure their applications fail gracefully when the input takes inappropriate amounts of memory or CPU to process.

Therefore we will no longer accept Denial of Service reports as security vulnerabilities. We will still consider reports where Xerces-C++ processes external paths (when it is correctly configured not to), or where it allows arbitrary code execution.


Reporting
 

To report a problem where Xerces-C++ behaves in a way that violates the security model described above, please use the ASF-wide reporting process.


Unaddressed Issues
 

The following security advisories apply to all released versions and are not believed to have been addressed. The project does not vouch for the accuracy of any advisories created by third parties but will publish any that appear credible.


Addressed in 3.2.5 and Later Releases
 

The following security advisories apply to versions of Xerces-C older than V3.2.5:


Addressed in 3.2.1 and Later Releases
 

The following security advisories apply to versions of Xerces-C older than V3.2.1:


Addressed in 3.1.4 and Later Releases
 

The following security advisories apply to versions of Xerces-C older than V3.1.4:


Addressed in 3.1.3 and Later Releases
 

The following security advisories apply to versions of Xerces-C older than V3.1.3:


Addressed in 3.1.2 and Later Releases
 

The following security advisories apply to versions of Xerces-C older than V3.1.2:



Copyright © 1999-2017 The Apache Software Foundation. All Rights Reserved.