Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-23807

Опубликовано: 29 фев. 2024
Источник: nvd
CVSS3: 9.8
CVSS3: 8.1
EPSS Низкий

Описание

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs.

Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.

This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:xerces-c\+\+:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.2.5 (исключая)

EPSS

Процентиль: 66%
0.00513
Низкий

9.8 Critical

CVSS3

8.1 High

CVSS3

Дефекты

CWE-416
CWE-416

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 2 года назад

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.

CVSS3: 8.1
redhat
почти 2 года назад

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.

CVSS3: 9.8
msrc
около 1 года назад

Описание отсутствует

CVSS3: 9.8
debian
почти 2 года назад

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contai ...

CVSS3: 8.1
github
почти 2 года назад

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.

EPSS

Процентиль: 66%
0.00513
Низкий

9.8 Critical

CVSS3

8.1 High

CVSS3

Дефекты

CWE-416
CWE-416