CVE-2015-0252

internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.
References
Link Resource
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152882.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153094.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153829.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153887.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153903.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153923.html
http://lists.opensuse.org/opensuse-updates/2016-04/msg00012.html
http://packetstormsecurity.com/files/131756/Apache-Xerces-C-XML-Parser-Denial-Of-Service.html
http://rhn.redhat.com/errata/RHSA-2015-1193.html
http://www.debian.org/security/2015/dsa-3199
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
http://www.securityfocus.com/bid/73252
http://www.securitytracker.com/id/1032254
http://xerces.apache.org/xerces-c/secadv/CVE-2015-0252.txt Vendor Advisory
https://shibboleth.net/community/advisories/secadv_20150319.txt
https://www.exploit-db.com/exploits/36906/
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152882.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153094.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153829.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153887.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153903.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153923.html
http://lists.opensuse.org/opensuse-updates/2016-04/msg00012.html
http://packetstormsecurity.com/files/131756/Apache-Xerces-C-XML-Parser-Denial-Of-Service.html
http://rhn.redhat.com/errata/RHSA-2015-1193.html
http://www.debian.org/security/2015/dsa-3199
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
http://www.securityfocus.com/bid/73252
http://www.securitytracker.com/id/1032254
http://xerces.apache.org/xerces-c/secadv/CVE-2015-0252.txt Vendor Advisory
https://shibboleth.net/community/advisories/secadv_20150319.txt
https://www.exploit-db.com/exploits/36906/
Configurations

Configuration 1 (hide)

cpe:2.3:o:debian:debian_linux:7.1:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:21:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:apache:xerces-c\+\+:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:22

Type Values Removed Values Added
References () http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152882.html - () http://lists.fedoraproject.org/pipermail/package-announce/2015-March/152882.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153094.html - () http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153094.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153829.html - () http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153829.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153887.html - () http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153887.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153903.html - () http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153903.html -
References () http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153923.html - () http://lists.fedoraproject.org/pipermail/package-announce/2015-March/153923.html -
References () http://lists.opensuse.org/opensuse-updates/2016-04/msg00012.html - () http://lists.opensuse.org/opensuse-updates/2016-04/msg00012.html -
References () http://packetstormsecurity.com/files/131756/Apache-Xerces-C-XML-Parser-Denial-Of-Service.html - () http://packetstormsecurity.com/files/131756/Apache-Xerces-C-XML-Parser-Denial-Of-Service.html -
References () http://rhn.redhat.com/errata/RHSA-2015-1193.html - () http://rhn.redhat.com/errata/RHSA-2015-1193.html -
References () http://www.debian.org/security/2015/dsa-3199 - () http://www.debian.org/security/2015/dsa-3199 -
References () http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html - () http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html -
References () http://www.securityfocus.com/bid/73252 - () http://www.securityfocus.com/bid/73252 -
References () http://www.securitytracker.com/id/1032254 - () http://www.securitytracker.com/id/1032254 -
References () http://xerces.apache.org/xerces-c/secadv/CVE-2015-0252.txt - Vendor Advisory () http://xerces.apache.org/xerces-c/secadv/CVE-2015-0252.txt - Vendor Advisory
References () https://shibboleth.net/community/advisories/secadv_20150319.txt - () https://shibboleth.net/community/advisories/secadv_20150319.txt -
References () https://www.exploit-db.com/exploits/36906/ - () https://www.exploit-db.com/exploits/36906/ -

Information

Published : 2015-03-24 17:59

Updated : 2024-11-21 02:22


NVD link : CVE-2015-0252

Mitre link : CVE-2015-0252

CVE.ORG link : CVE-2015-0252


JSON object : View

Products Affected

debian

  • debian_linux

fedoraproject

  • fedora

apache

  • xerces-c\+\+
CWE
CWE-20

Improper Input Validation