Xerces-C++ 'maxOccurs' XML Parsing Remote Denial of Service Vulnerability
BID:31533
Info
Xerces-C++ 'maxOccurs' XML Parsing Remote Denial of Service Vulnerability
| Bugtraq ID: | 31533 |
| Class: | Design Error |
| CVE: |
CVE-2008-4482 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2008 12:00AM |
| Updated: | Mar 10 2009 07:56PM |
| Credit: | Frank Rast |
| Vulnerable: |
Gentoo Linux Apache Xerces C++ 2.8 Apache Xerces C++ 2.6 .0 Apache Xerces C++ 2.5 .0 Apache Xerces C++ 2.2 Apache Xerces C++ 2.1 .0 Apache Xerces C++ 1.7 |
| Not Vulnerable: |
Apache Xerces C++ 3.0 |
Discussion
Xerces-C++ 'maxOccurs' XML Parsing Remote Denial of Service Vulnerability
Xerces-C++ is prone to a denial-of-service vulnerability because it fails to handle certain XML schema values.
Exploiting this issue allows remote attackers to cause denial-of-service conditions in the context of an application using the vulnerable XML parsing library.
Versions prior to Xerces-C++ 3.0.0 are affected.
Xerces-C++ is prone to a denial-of-service vulnerability because it fails to handle certain XML schema values.
Exploiting this issue allows remote attackers to cause denial-of-service conditions in the context of an application using the vulnerable XML parsing library.
Versions prior to Xerces-C++ 3.0.0 are affected.
Exploit / POC
Xerces-C++ 'maxOccurs' XML Parsing Remote Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Xerces-C++ 'maxOccurs' XML Parsing Remote Denial of Service Vulnerability
Solution:
The vendor released Xerces-C++ 3.0.0 to address this issue. Please see the references for more information.
Apache Xerces C++ 1.7
Apache Xerces C++ 2.1 .0
Apache Xerces C++ 2.2
Apache Xerces C++ 2.5 .0
Apache Xerces C++ 2.6 .0
Apache Xerces C++ 2.8
Solution:
The vendor released Xerces-C++ 3.0.0 to address this issue. Please see the references for more information.
Apache Xerces C++ 1.7
-
Apache Software Foundation xerces-c-3.0.0.tar.gz
http://apache.sunsite.ualberta.ca/xerces/c/3/sources/xerces-c-3.0.0.ta r.gz
Apache Xerces C++ 2.1 .0
-
Apache Software Foundation xerces-c-3.0.0.tar.gz
http://apache.sunsite.ualberta.ca/xerces/c/3/sources/xerces-c-3.0.0.ta r.gz
Apache Xerces C++ 2.2
-
Apache Software Foundation xerces-c-3.0.0.tar.gz
http://apache.sunsite.ualberta.ca/xerces/c/3/sources/xerces-c-3.0.0.ta r.gz
Apache Xerces C++ 2.5 .0
-
Apache Software Foundation xerces-c-3.0.0.tar.gz
http://apache.sunsite.ualberta.ca/xerces/c/3/sources/xerces-c-3.0.0.ta r.gz
Apache Xerces C++ 2.6 .0
-
Apache Software Foundation xerces-c-3.0.0.tar.gz
http://apache.sunsite.ualberta.ca/xerces/c/3/sources/xerces-c-3.0.0.ta r.gz
Apache Xerces C++ 2.8
-
Apache Software Foundation xerces-c-3.0.0.tar.gz
http://apache.sunsite.ualberta.ca/xerces/c/3/sources/xerces-c-3.0.0.ta r.gz
References
Xerces-C++ 'maxOccurs' XML Parsing Remote Denial of Service Vulnerability
References:
References:
- Crash when maxOccurs >= 200000 (Frank Rast)
- Release Information for Xerces-C++ 3.0.0 (Apache Software Foundation)
- Xerces C++ Homepage (Apache Software Foundation)