Описание
In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| xerces-c | fixed | 3.2.1+debian-1 | package | |
| xerces-c | fixed | 3.1.4+debian-2+deb9u1 | stretch | package |
| xerces-c | fixed | 3.1.1-5.1+deb8u4 | jessie | package |
Примечания
https://svn.apache.org/r1819998
https://xerces.apache.org/xerces-c/secadv/CVE-2017-12627.txt
EPSS
Процентиль: 88%
0.03883
Низкий
Связанные уязвимости
CVSS3: 9.8
ubuntu
почти 8 лет назад
In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.
CVSS3: 7.5
redhat
почти 8 лет назад
In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.
CVSS3: 9.8
nvd
почти 8 лет назад
In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.
EPSS
Процентиль: 88%
0.03883
Низкий