Back

CRITICAL

xerces-c: Null pointer dereference while processing the path to DTD allows denial of service

Published Mar 1, 2018

Description

In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise MRG and MRG-Messaging are currently in Maintenance phase. This issue has been rated as having Moderate security impact, and is not currently planned to be addressed in future releases of MRG or MRG-Messaging. For more information, refer to the Issue Severity Classification and the Life Cycle and Update Policies: https://access.redhat.com/security/updates/classification https://access.redhat.com/support/policy/update_policies/

Red Hat mitigation

Applications should strongly consider blocking remote entity resolution and/or outright disabling of DTD processing in light of the continued identification of bugs in this area of the library.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Mar 1, 2018
Updated Sep 17, 2024
Reserved Aug 7, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 1, 2018