PT-2023-6251 · Apache+6 · Xerces-C+++6

Even Rouault

·

Published

2023-10-11

·

Updated

2025-01-13

·

CVE-2023-37536

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xerces-c++ version 3.2.3
Description The issue is caused by an integer overflow in xerces-c++ that allows remote attackers to cause out-of-bound access via an HTTP request. This can potentially allow a remote attacker to execute arbitrary code by sending a specially crafted HTTP request.
Recommendations For xerces-c++ version 3.2.3, consider updating to a newer version that contains a fix for this issue, as the current version allows remote attackers to cause out-of-bound access via HTTP requests. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-8078
ALT-PU-2024-8410
BDU:2023-06960
CVE-2023-37536
DLA-3704-1
OPENSUSE-SU-2023_4586-1
RHSA-2024:8795
ROSA-SA-2025-2562
SUSE-SU-2023:4543-1
SUSE-SU-2023:4586-1
SUSE-SU-2023:4715-1
SUSE-SU-2023_4543-1
SUSE-SU-2023_4586-1
SUSE-SU-2023_4715-1
USN-6590-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Red Os
Suse
Ubuntu
Xerces-C++