Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-2625

Опубликовано: 05 авг. 2009
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux Extended Update Support 5.3java-1.6.0-openjdkAffected
Red Hat Enterprise Linux Extended Update Support 5.5java-1.6.0-ibmAffected
Red Hat Enterprise Linux Extended Update Support 5.8xerces-j2Affected
Red Hat Enterprise Linux Extended Update Support 6.0xerces-j2Affected
Red Hat Satellite 4.2ServerAffected
Red Hat Satellite 5.0ServerAffected
Extras for RHEL 3java-1.4.2-ibmFixedRHSA-2009:150514.10.2009
Extras for RHEL 4java-1.5.0-sunFixedRHSA-2009:119906.08.2009
Extras for RHEL 4java-1.6.0-sunFixedRHSA-2009:120006.08.2009
Extras for RHEL 4java-1.5.0-ibmFixedRHSA-2009:123628.08.2009

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=512921JDK: XML parsing Denial-Of-Service (6845701)

EPSS

Процентиль: 55%
0.00326
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 16 лет назад

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

nvd
почти 16 лет назад

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

debian
почти 16 лет назад

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime En ...

github
около 5 лет назад

Denial of service in Apache Xerces2

oracle-oval
около 14 лет назад

ELSA-2011-0858: xerces-j2 security update (MODERATE)

EPSS

Процентиль: 55%
0.00326
Низкий

5 Medium

CVSS2