PT-2009-6723 · Oracle+3 · Jre+8

Marc Schoenefeld

·

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-2625

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Apache Xerces2 Java versions prior to JDK and JRE 6 Update 15 Apache Xerces2 Java versions prior to JDK and JRE 5.0 Update 20 libxerces2-java-gcj (affected versions not specified) libxerces2-java-doc (affected versions not specified) libxerces2-java (affected versions not specified)
Description The issue allows remote attackers to cause a denial of service, resulting in an infinite loop and application hang, via malformed XML input. This can be demonstrated by the Codenomicon XML fuzzing framework. The exploitation of the vulnerabilities can lead to a disruption of protected information and can be carried out remotely.
Recommendations For Apache Xerces2 Java versions prior to JDK and JRE 6 Update 15, update to JDK and JRE 6 Update 15 or later. For Apache Xerces2 Java versions prior to JDK and JRE 5.0 Update 20, update to JDK and JRE 5.0 Update 20 or later. For libxerces2-java-gcj, libxerces2-java-doc, and libxerces2-java, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-04031
BDU:2015-04032
BDU:2015-04033
CVE-2009-2625
DSA-1984-1
GHSA-334P-WV2M-W3VP
HPSBUX02476
OPENSUSE-SU-2024:10077-1
RHSA-2009:1199
RHSA-2009:1200
RHSA-2009:1201
RHSA-2009:1236
RHSA-2009:1505
RHSA-2009:1551
RHSA-2009:1582
RHSA-2009:1615
RHSA-2009:1636
RHSA-2009:1637
RHSA-2009:1649
RHSA-2009:1650
RHSA-2009:1662
RHSA-2009_1201
RHSA-2009_1615
RHSA-2010:0043
RHSA-2011:0858
RHSA-2011_0858
RHSA-2012:1537

Affected Products

Apache Xerces2 Java
Hp-Ux
Jdk
Jre
Java Platform
Red Hat
Libxerces2-Java
Libxerces2-Java-Doc
Libxerces2-Java-Gcj