It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer dereferences when processing malformed XML data. Upstream Bug: https://issues.apache.org/jira/projects/SANTUARIO/issues/SANTUARIO-491 Upstream Patch: https://svn.apache.org/viewvc?view=revision&revision=1837240
Created xml-security-c tracking bugs for this issue: Affects: epel-all [bug 1614635] Affects: fedora-all [bug 1614634]
*** This bug has been marked as a duplicate of bug 1612388 ***