CVE-2009-2625
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 30.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 30.38% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- oracle/jdk · fedoraproject/fedora · opensuse/opensuse · suse/linux enterprise server · debian/debian linux · canonical/ubuntu linux · oracle/primavera p6 enterprise project portfolio management · oracle/primavera web services · apache/xerces2 java
- Source
- cret@cert.org
References
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=125787273209737&w=2Mailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1232.htmlBroken Link
- http://rhn.redhat.com/errata/RHSA-2012-1537.htmlBroken Link
- http://secunia.com/advisories/36162Third Party Advisory
- http://secunia.com/advisories/36176Third Party Advisory
- http://secunia.com/advisories/36180Third Party Advisory
- http://secunia.com/advisories/36199Third Party Advisory
- http://secunia.com/advisories/37300Third Party Advisory
- http://secunia.com/advisories/37460Third Party Advisory
- http://secunia.com/advisories/37671Third Party Advisory
- http://secunia.com/advisories/37754Third Party Advisory
- http://secunia.com/advisories/38231Third Party Advisory
- http://secunia.com/advisories/38342Third Party Advisory
- http://secunia.com/advisories/43300Third Party Advisory
- http://secunia.com/advisories/50549Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2011&m=slackware-security.486026Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1Broken Link, Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-263489-1Broken Link, Patch, Vendor Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-272209-1Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021506.1-1Broken Link
- http://svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java?r1=572055&r2=787352&pathrev=787353&diff_format=hPatch, Vendor Advisory
- http://www.cert.fi/en/reports/2009/vulnerability2009085.htmlThird Party Advisory
- http://www.codenomicon.com/labs/xml/Third Party Advisory
- http://www.debian.org/security/2010/dsa-1984Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:209Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.