Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4463

Опубликовано: 29 июн. 2016
Источник: redhat
CVSS3: 4.7
CVSS2: 4.3
EPSS Средний

Описание

Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.

A stack exhaustion flaw was found in the way Xerces-C XML parser handled deeply nested DTDs. An attacker could potentially use this flaw to crash an application using Xerces-C by tricking it into processing specially crafted data.

Отчет

Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/ and Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6xerces-cWill not fix
Red Hat Enterprise MRG 2xerces-cUnder investigation
Red Hat Enterprise MRG 3xerces-cUnder investigation
Red Hat OpenShift Enterprise 2xerces-cUnder investigation
Red Hat Enterprise Linux 7xerces-cFixedRHSA-2018:333530.10.2018
Red Hat Enterprise Linux 7.4 Extended Update Supportxerces-cFixedRHSA-2018:351406.11.2018
Red Hat Enterprise Linux 7.5 Extended Update Supportxerces-cFixedRHSA-2018:350606.11.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=1348845xerces-c: Stack overflow when parsing deeply nested DTD

EPSS

Процентиль: 97%
0.32071
Средний

4.7 Medium

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.

CVSS3: 7.5
nvd
больше 9 лет назад

Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.

CVSS3: 7.5
debian
больше 9 лет назад

Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows c ...

CVSS3: 7.5
github
больше 3 лет назад

Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.

oracle-oval
около 7 лет назад

ELSA-2018-3335: xerces-c security update (MODERATE)

EPSS

Процентиль: 97%
0.32071
Средний

4.7 Medium

CVSS3

4.3 Medium

CVSS2