QID 198677

Date Published: 2022-02-24

QID 198677: Ubuntu Security Notification for c3p0 Vulnerability (USN-5293-1)

C3p0 could be made to crash whenparsing certain input.

An attacker able to modify the application'sxml configuration file could cause a denial of service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5293-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198677

    Software Advisories
    Advisory ID Software Component Link
    USN-5293-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5293-1