Описание
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libxerces2-java | fixed | 2.12.2-1 | package | |
| libxerces2-java | postponed | bullseye | package | |
| libxerces2-java | postponed | buster | package | |
| libxerces2-java | postponed | stretch | package |
Примечания
https://www.openwall.com/lists/oss-security/2022/01/24/3
https://issues.apache.org/jira/browse/XERCESJ-1737
Confimation of fixing commits: https://lists.apache.org/thread/8bdbk40hf1oqhyvmdcvtqwr2hwfhhmkt
The svn.apache.org links are gone, but looking at the Wayback Machine it's these commits:
https://github.com/apache/xerces-j/commit/0a785cfe0d210b5e5b3b020ecfeb67693764aaf4
https://github.com/apache/xerces-j/commit/da8efa66241dd63cb34eacb22bc28c3469af91a6
EPSS
Связанные уязвимости
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
EPSS