LWN.net Logo

xerces-c: denial of service

Package(s):xerces-c CVE #(s):CVE-2008-4482
Created:March 9, 2009 Updated:March 11, 2009
Description:

From the Gentoo advisory:

Frank Rast reported that the XML parser in Xerces-C++ does not correctly handle an XML schema definition with a large maxOccurs value, which triggers excessive memory consumption during the validation of an XML file.

A remote attacker could entice a user or automated system to validate an XML file using a specially crafted XML schema file, leading to a Denial of Service (stack consumption and crash).

Alerts:
Gentoo 200903-19 2009-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds