Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-23807

Опубликовано: 29 фев. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.8

Описание

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

3.2.4+debian-1.3build2
esm-apps/bionic

released

3.2.0+debian-2ubuntu0.1~esm2
esm-apps/focal

released

3.2.2+debian-1ubuntu0.1
esm-apps/jammy

released

3.2.3+debian-3ubuntu0.1~esm1
esm-apps/noble

not-affected

3.2.4+debian-1.2ubuntu2
esm-apps/xenial

released

3.1.3+debian-1ubuntu0.1~esm2
esm-infra-legacy/trusty

released

3.1.1-5.1+deb8u4ubuntu0.1~esm1
focal

ignored

end of standard support, was needs-triage
jammy

released

3.2.3+debian-3ubuntu0.1

Показывать по

Ссылки на источники

EPSS

Процентиль: 66%
0.00513
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
почти 2 года назад

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.

CVSS3: 9.8
nvd
почти 2 года назад

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.

CVSS3: 9.8
msrc
около 1 года назад

Описание отсутствует

CVSS3: 9.8
debian
почти 2 года назад

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contai ...

CVSS3: 8.1
github
почти 2 года назад

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.

EPSS

Процентиль: 66%
0.00513
Низкий

9.8 Critical

CVSS3