PT-2015-4544 · Apache+4 · Apache Xerces-C+4

Beford

·

Publicado

2015-03-09

·

Atualizado

2023-02-06

·

CVE-2015-0252

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Xerces-C versions prior to 3.1.2
Description The issue allows remote attackers to cause a denial of service, resulting in a segmentation fault and crash, via crafted XML data. This is due to a problem in the internal/XMLReader.cpp file.
Recommendations For versions prior to 3.1.2, update to version 3.1.2 or later to resolve the issue. As a temporary workaround, consider restricting the input of crafted XML data to minimize the risk of exploitation.

Exploit

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2015-1695
CESA-2015_1193
CVE-2015-0252
DLA-181-1
DSA-3199-1
MGASA-2015-0136
RHSA-2015:1193
RHSA-2015_1193
SUSE-SU-2015:0597-1
SUSE-SU-2015_0597-1

Produtos afetados

Alt Linux
Apache Xerces-C
Centos
Red Hat
Suse