Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS03ajRoLTh3cGYtcnFmaM3mvw

Missing XML Validation in Apache Xerces2

XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.

Permalink: https://github.com/advisories/GHSA-7j4h-8wpf-rqfh
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03ajRoLTh3cGYtcnFmaM3mvw
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: about 2 months ago


Identifiers: GHSA-7j4h-8wpf-rqfh, CVE-2013-4002
References: Repository: https://svn.apache.org/viewvc/xerces/java
Blast Radius: 0.0

Affected Packages

maven:xerces:xercesImpl
Dependent packages: 1,930
Dependent repositories: 17,907
Downloads:
Affected Version Ranges: < 2.12.0
Fixed in: 2.12.0
All affected versions: 2.0.0, 2.0.2, 2.2.1, 2.3.0, 2.4.0, 2.5.0, 2.6.0, 2.6.1, 2.6.2, 2.7.1, 2.8.0, 2.8.1, 2.9.0, 2.9.1, 2.10.0, 2.11.0
All unaffected versions: 2.12.0, 2.12.1, 2.12.2