CVE-2017-12627

In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:xerces-c\+\+:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:09

Type Values Removed Values Added
References () http://seclists.org/oss-sec/2018/q1/203 - Mailing List, Third Party Advisory () http://seclists.org/oss-sec/2018/q1/203 - Mailing List, Third Party Advisory
References () http://www.securityfocus.com/bid/103219 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/103219 - Third Party Advisory, VDB Entry
References () http://xerces.apache.org/xerces-c/secadv/CVE-2017-12627.txt - Vendor Advisory () http://xerces.apache.org/xerces-c/secadv/CVE-2017-12627.txt - Vendor Advisory
References () https://kc.mcafee.com/corporate/index?page=content&id=SB10365 - () https://kc.mcafee.com/corporate/index?page=content&id=SB10365 -
References () https://lists.debian.org/debian-lts-announce/2018/03/msg00032.html - () https://lists.debian.org/debian-lts-announce/2018/03/msg00032.html -

Information

Published : 2018-03-01 14:29

Updated : 2024-11-21 03:09


NVD link : CVE-2017-12627

Mitre link : CVE-2017-12627

CVE.ORG link : CVE-2017-12627


JSON object : View

Products Affected

apache

  • xerces-c\+\+
CWE
CWE-476

NULL Pointer Dereference