Xerces C++ Duplicated Attributes XML Parsing Denial Of Service Vulnerability
BID:11312
Info
Xerces C++ Duplicated Attributes XML Parsing Denial Of Service Vulnerability
| Bugtraq ID: | 11312 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2004 12:00AM |
| Updated: | Oct 02 2004 12:00AM |
| Credit: | Amit Klein (AKsecurity) <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Apache Xerces C++ 2.5 .0 |
| Not Vulnerable: |
Apache Xerces C++ 2.6 .0 |
Discussion
Xerces C++ Duplicated Attributes XML Parsing Denial Of Service Vulnerability
It is reported that Xerces C++ is susceptible to a denial of service vulnerability. This issue is due to a failure of the application to properly handle exceptional XML input.
This vulnerability allows remote attackers to consume all available CPU resources by passing maliciously crafted XML data to an application that utilizes the affected library.
Version 2.5.0 of Xerces C++ is reported to be affected by this vulnerability. Other prior versions may also be affected.
It is reported that Xerces C++ is susceptible to a denial of service vulnerability. This issue is due to a failure of the application to properly handle exceptional XML input.
This vulnerability allows remote attackers to consume all available CPU resources by passing maliciously crafted XML data to an application that utilizes the affected library.
Version 2.5.0 of Xerces C++ is reported to be affected by this vulnerability. Other prior versions may also be affected.
Exploit / POC
Xerces C++ Duplicated Attributes XML Parsing Denial Of Service Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Xerces C++ Duplicated Attributes XML Parsing Denial Of Service Vulnerability
Solution:
The vendor has released version 2.6.0 of Xerces C++ to address this issue:
Apache Xerces C++ 2.5 .0
Solution:
The vendor has released version 2.6.0 of Xerces C++ to address this issue:
Apache Xerces C++ 2.5 .0
-
Apache Software Foundation xerces-c-src_2_6_0.tar.gz
http://www.apache.org/dist/xml/xerces-c/xerces-c-src_2_6_0.tar.gz
References
Xerces C++ Duplicated Attributes XML Parsing Denial Of Service Vulnerability
References:
References:
- Xerces C++ 2.6.0 Release Announcement (Apache Software Foundation)
- Xerces C++ Homepage (Apache Software Foundation)
- Xerces C++ Release Information (Apache Software Foundation)
- Security advisory - Xerces-C++ 2.5.0: Attribute blowup ("Amit Klein \(AKsecurity\)"
)