Back

MEDIUM

xerces-c27: Stack overflow when parsing recursive XML structures

Published Aug 11, 2009

Description

Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Metrics

References (18)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 11, 2009
Updated Aug 7, 2024
Reserved Jun 2, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Aug 5, 2009