CVE-2009-1885
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.
Vulnerabilidad de agotamiento de pila en validators/DTD/DTDScanner.cpp en Apache Xerces C++ v2.7.0 y v2.8.0 permite a atacantes dependientes de contexto producir una denegación de servicio (caída de aplicación) a través de vectores que incluyen el uso de paréntesis anidados y unos valores de byte no validos en "estructuras simples anidadas DTD", como se demostro en Codenomicon XML fuzzing framework.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-06-02 CVE Reserved
- 2009-08-11 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (15)
URL | Tag | Source |
---|---|---|
http://svn.apache.org/viewvc/xerces/c/trunk/src/xercesc/validators/DTD/DTDScanner.cpp?r1=781488&r2=781487&pathrev=781488&view=patch | X_refsource_confirm | |
http://www.cert.fi/en/reports/2009/vulnerability2009085.html | X_refsource_misc | |
http://www.codenomicon.com/labs/xml | X_refsource_misc | |
http://www.networkworld.com/columnists/2009/080509-xml-flaw.html | X_refsource_misc | |
http://www.securityfocus.com/bid/35986 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/52321 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://svn.apache.org/viewvc?view=rev&revision=781488 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://www.vupen.com/english/advisories/2009/2196 | 2017-08-17 | |
https://bugzilla.redhat.com/show_bug.cgi?id=515515 | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Xerces-c\+\+ Search vendor "Apache" for product "Xerces-c\+\+" | 2.7.0 Search vendor "Apache" for product "Xerces-c\+\+" and version "2.7.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Xerces-c\+\+ Search vendor "Apache" for product "Xerces-c\+\+" | 2.8.0 Search vendor "Apache" for product "Xerces-c\+\+" and version "2.8.0" | - |
Affected
|