LWN.net Logo

expat: denial of service

Package(s):expat CVE #(s):CVE-2009-2625
Created:August 24, 2009 Updated:June 13, 2011
Description:

From the Gentoo bug report:

Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

Alerts:
Mandriva MDVSA-2011:108 2011-06-13
Scientific Linux SL-xerc-20110608 2011-06-08
Slackware SSA:2011-041-02 2011-02-11
SUSE SUSE-SR:2010:015 2010-08-17
SUSE SUSE-SR:2010:014 2010-08-02
SuSE SUSE-SR:2010:012 2010-05-25
SuSE SUSE-SR:2010:011 2010-05-10
SuSE SUSE-SR:2010:013 2010-06-14
Ubuntu USN-890-6 2010-04-15
Ubuntu USN-890-4 2010-01-26
Ubuntu USN-890-3 2010-01-22
Ubuntu USN-890-2 2010-01-21
Ubuntu USN-890-1 2010-01-20
Mandriva MDVSA-2009:316-1 2010-01-08
Mandriva MDVSA-2009:220-1 2010-01-05
CentOS CESA-2009:1615 2009-12-17
Mandriva MDVSA-2009:212-1 2009-12-04
Mandriva MDVSA-2009:213-1 2009-12-04
Mandriva MDVSA-2009:211-1 2009-12-04
Mandriva MDVSA-2009:218-1 2009-12-04
Mandriva MDVSA-2009:217-3 2009-12-03
SuSE SUSE-SR:2010:005 2010-02-23
Ubuntu USN-890-5 2010-02-18
Red Hat RHSA-2009:1236-01 2009-08-28
Mandriva MDVSA-2009:220 2009-08-24
Mandriva MDVSA-2009:219 2009-08-24
Mandriva MDVSA-2009:218 2009-08-24
Mandriva MDVSA-2009:217 2009-08-23
Mandriva MDVSA-2009:216 2009-08-23
Mandriva MDVSA-2009:215 2009-08-23
Mandriva MDVSA-2009:214 2009-08-23
Mandriva MDVSA-2009:213 2009-08-23
Mandriva MDVSA-2009:212 2009-08-23
Mandriva MDVSA-2009:211 2009-08-23
SuSE SUSE-SA:2009:053 2009-11-04
Debian DSA-1984-1 2010-01-30
Debian DSA-1921-1 2009-10-28
Red Hat RHSA-2009:1615-01 2009-11-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds