CVE-2018-1311
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 9.50% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-416
- Affected
- apache/xerces-c\+\+ · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · debian/debian linux · oracle/goldengate · fedoraproject/fedora
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2024/02/16/1Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0702Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0704Third Party Advisory
- https://lists.apache.org/thread.html/r48ea463fde218b1e4cc1a1d05770a0cea34de0600b4355315a49226b%40%3Cc-dev.xerces.apache.org%3EVendor Advisory
- https://lists.apache.org/thread.html/r90ec105571622a7dc3a43b846c12732d2e563561dfb2f72941625f35%40%3Cc-users.xerces.apache.org%3EIssue Tracking
- https://lists.apache.org/thread.html/rabbcc0249de1dda70cda96fd9bcff78217be7a57d96e7dcc8cd96646%40%3Cc-users.xerces.apache.org%3EIssue Tracking
- https://lists.apache.org/thread.html/rfeb8abe36bcca91eb603deef49fbbe46870918830a66328a780b8625%40%3Cc-users.xerces.apache.org%3EIssue Tracking
- https://lists.debian.org/debian-lts-announce/2020/12/msg00025.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/12/msg00027.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A6WWL4SWKAVYK6VK5YN7KZP4MZWC7IY/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/Mailing List, Third Party Advisory
- https://marc.info/?l=xerces-c-users&m=157653840106914&w=2Mailing List, Third Party Advisory
- https://www.debian.org/security/2020/dsa-4814Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2024/02/16/1Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0702Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0704Third Party Advisory
- https://lists.apache.org/thread.html/r48ea463fde218b1e4cc1a1d05770a0cea34de0600b4355315a49226b%40%3Cc-dev.xerces.apache.org%3EVendor Advisory
- https://lists.apache.org/thread.html/r90ec105571622a7dc3a43b846c12732d2e563561dfb2f72941625f35%40%3Cc-users.xerces.apache.org%3EIssue Tracking
- https://lists.apache.org/thread.html/rabbcc0249de1dda70cda96fd9bcff78217be7a57d96e7dcc8cd96646%40%3Cc-users.xerces.apache.org%3EIssue Tracking
- https://lists.apache.org/thread.html/rfeb8abe36bcca91eb603deef49fbbe46870918830a66328a780b8625%40%3Cc-users.xerces.apache.org%3EIssue Tracking
- https://lists.debian.org/debian-lts-announce/2020/12/msg00025.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/12/msg00027.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A6WWL4SWKAVYK6VK5YN7KZP4MZWC7IY/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/
- https://marc.info/?l=xerces-c-users&m=157653840106914&w=2Mailing List, Third Party Advisory
- https://www.debian.org/security/2020/dsa-4814Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.