|
|
| |
|
| |
xerces-c: denial of service
| Package(s): | xerces-c |
CVE #(s): | CVE-2008-4482
|
| Created: | March 9, 2009 |
Updated: | March 11, 2009 |
| Description: |
From the Gentoo advisory:
Frank Rast reported that the XML parser in Xerces-C++ does not
correctly handle an XML schema definition with a large maxOccurs value,
which triggers excessive memory consumption during the validation of an
XML file.
A remote attacker could entice a user or automated system to validate
an XML file using a specially crafted XML schema file, leading to a
Denial of Service (stack consumption and crash).
|
| Alerts: |
|
( Log in to post comments)
|
|
|