Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0252

Опубликовано: 20 мар. 2015
Источник: redhat
CVSS2: 5
EPSS Средний

Описание

internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.

A flaw was found in the way the Xerces-C XML parser processed certain XML documents. A remote attacker could provide specially crafted XML input that, when parsed by an application using Xerces-C, would cause that application to crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xerces-cWill not fix
Red Hat Enterprise MRG 2xerces-cWill not fix
Red Hat Enterprise MRG 3xerces-cWill not fix
Red Hat OpenShift Enterprise 2xerces-cWill not fix
Red Hat Enterprise Linux 7xerces-cFixedRHSA-2015:119329.06.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1199103xerces-c: crashes on malformed input

EPSS

Процентиль: 96%
0.26743
Средний

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.

nvd
больше 10 лет назад

internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.

debian
больше 10 лет назад

internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote a ...

suse-cvrf
больше 10 лет назад

Security update for Xerces-C

github
больше 3 лет назад

internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.

EPSS

Процентиль: 96%
0.26743
Средний

5 Medium

CVSS2