PT-2018-2310 · Apache+3 · Apache Xerces-C Xml Parser+3

Alberto Garcia

+2

·

Published

2018-03-01

·

Updated

2024-06-15

·

CVE-2017-12627

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Xerces-C XML Parser library versions prior to 3.2.1
Description The issue is related to the incorrect processing of external DTD paths in the Apache Xerces-C XML Parser library, which can lead to a null pointer dereference under certain conditions. This can potentially allow a remote attacker to cause a denial of service.
Recommendations For versions prior to 3.2.1, update to version 3.2.1 or later to resolve the issue. As a temporary workaround, consider restricting the processing of external DTD paths until a patch is available.

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1758
BDU:2019-00445
CVE-2017-12627
DLA-1328-1
MGASA-2018-0158
MGASA-2018-0178
OPENSUSE-SU-2019:1283-1
OPENSUSE-SU-2019_1283-1
OPENSUSE-SU-2024:11521-1
SUSE-SU-2018:3277-1
SUSE-SU-2019:0977-1
SUSE-SU-2019_0977-1
SUSE-SU-2020:2225-1
SUSE-SU-2020_2225-1
USN-4784-1

Affected Products

Alt Linux
Apache Xerces-C Xml Parser
Suse
Ubuntu