PT-2018-2310 · Apache+3 · Apache Xerces-C Xml Parser+3

Alberto Garcia

+2

·

Publicado

2018-03-01

·

Atualizado

2024-06-15

·

CVE-2017-12627

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Xerces-C XML Parser library versions prior to 3.2.1
Description The issue is related to the incorrect processing of external DTD paths in the Apache Xerces-C XML Parser library, which can lead to a null pointer dereference under certain conditions. This can potentially allow a remote attacker to cause a denial of service.
Recommendations For versions prior to 3.2.1, update to version 3.2.1 or later to resolve the issue. As a temporary workaround, consider restricting the processing of external DTD paths until a patch is available.

Correção

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1758
BDU:2019-00445
CVE-2017-12627
DLA-1328-1
MGASA-2018-0158
MGASA-2018-0178
OPENSUSE-SU-2019:1283-1
OPENSUSE-SU-2019_1283-1
OPENSUSE-SU-2024:11521-1
SUSE-SU-2018:3277-1
SUSE-SU-2019:0977-1
SUSE-SU-2019_0977-1
SUSE-SU-2020:2225-1
SUSE-SU-2020_2225-1
USN-4784-1

Produtos afetados

Alt Linux
Apache Xerces-C Xml Parser
Suse
Ubuntu