xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs
Published Dec 18, 2019
8.1
HIGHCVSS 3.1
EPSS 9.50%
Description
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
Affected products
-
- Version 3.0.0 to 3.2.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Xerces-C | n/a |
|
Configuration 1
- ≥ 3.0.0 · < 3.2.5
Configuration 2
- 6.0
- 7.0
- 7.7
- 6.0
- 7.0
- 7.7
- 7.7
- 6.0
- 7.0
Configuration 3
- 9.0
- 10.0
Configuration 4
- < 21.4.0.0.0
Configuration 5
- 38
- 39
No data.
Red Hat Enterprise Linux 6
xerces-c-0:3.0.1-21.el6_10
Fixed · RHSA-2020:0702
Red Hat Enterprise Linux 7
xerces-c-0:3.1.1-10.el7_7
Fixed · RHSA-2020:0704
Red Hat Enterprise MRG 3
xerces-c
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | xerces-c-0:3.0.1-21.el6_10 | Fixed | RHSA-2020:0702 |
| Red Hat Enterprise Linux 7 | xerces-c-0:3.1.1-10.el7_7 | Fixed | RHSA-2020:0704 |
| Red Hat Enterprise MRG 3 | xerces-c | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Disable DTD processing by setting the environment variable `XERCES_DISABLE_DTD=1`. Please note that this feature was introduced in xerces-c upstream version 3.1.4 and is not available in older versions. The versions of xerces-c as shipped with Red Hat Enterprise Linux 6 and 7 did not include this feature.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (30 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 9.50% (0.09503) | 95.30th | v5 (v2026.06.15) |
| Jun 15, 2026 | 9.58% (0.09580) | 94.83th | v5 (v2026.06.15) |
| Nov 21, 2025 | 4.17% (0.04171) | 88.20th | v4 (v2025.03.14) |
| Nov 18, 2025 | 14.43% (0.14431) | 93.81th | v4 (v2025.03.14) |
| Sep 11, 2025 | 4.28% (0.04282) | 88.41th | v4 (v2025.03.14) |
| Sep 6, 2025 | 3.15% (0.03150) | 86.39th | v4 (v2025.03.14) |
| Mar 30, 2025 | 4.17% (0.04171) | 87.62th | v4 (v2025.03.14) |
| Mar 29, 2025 | 16.18% (0.16178) | 91.41th | v4 (v2025.03.14) |
| Mar 28, 2025 | 4.17% (0.04171) | 87.64th | v4 (v2025.03.14) |
| Mar 27, 2025 | 16.18% (0.16178) | 93.90th | v4 (v2025.03.14) |
| Mar 20, 2025 | 4.17% (0.04171) | 87.72th | v4 (v2025.03.14) |
| Mar 19, 2025 | 16.18% (0.16178) | 94.02th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.17% (0.04171) | 87.93th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.85% (0.00846) | 82.86th | v3 (v2023.03.01) |
| Jun 22, 2024 | 1.42% (0.01421) | 86.58th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.29% (0.00287) | 67.95th | v3 (v2023.03.01) |
| Jan 1, 2024 | 0.29% (0.00287) | 65.50th | v3 (v2023.03.01) |
| Dec 31, 2023 | 0.26% (0.00260) | 63.69th | v3 (v2023.03.01) |
| Nov 24, 2023 | 0.25% (0.00250) | 62.87th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.22% (0.00219) | 59.68th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.19% (0.00195) | 56.20th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.23% (0.00234) | 59.67th | v3 (v2023.03.01) |
| Mar 6, 2023 | 26.10% (0.26100) | 97.08th | v2 (v2022.01.01) |
| Feb 4, 2022 | 26.10% (0.26100) | 95.69th | v2 (v2022.01.01) |
| Feb 3, 2022 | 22.19% (0.22190) | 94.78th | v1 |
| Jan 21, 2022 | 22.19% (0.22190) | 94.75th | v1 |
| Jan 6, 2022 | 5.98% (0.05976) | 81.15th | v1 |
| Sep 1, 2021 | 5.98% (0.05976) | 89.53th | v1 |
| May 29, 2021 | 5.98% (0.05976) | 0.00th | v1 |
| Apr 14, 2021 | 4.25% (0.04249) | 0.00th | v1 |
References (19)
- http://www.openwall.com/lists/oss-security/2024/02/16/1 mailing-listMailing ListThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0702 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0704 vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-1311 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1788472 Issue Tracking
- https://lists.apache.org/thread.html/r48ea463fde218b1e4cc1a1d05770a0cea34de0600b4355315a49226b%40%3Cc-dev.xerces.apache.org%3E mailing-listVendor Advisory
- https://lists.apache.org/thread.html/r90ec105571622a7dc3a43b846c12732d2e563561dfb2f72941625f35%40%3Cc-users.xerces.apache.org%3E mailing-listIssue Tracking
- https://lists.apache.org/thread.html/rabbcc0249de1dda70cda96fd9bcff78217be7a57d96e7dcc8cd96646%40%3Cc-users.xerces.apache.org%3E mailing-listIssue Tracking
- https://lists.apache.org/thread.html/rfeb8abe36bcca91eb603deef49fbbe46870918830a66328a780b8625%40%3Cc-users.xerces.apache.org%3E mailing-listIssue Tracking
- https://lists.debian.org/debian-lts-announce/2020/12/msg00025.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/12/msg00027.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A6WWL4SWKAVYK6VK5YN7KZP4MZWC7IY/ vendor-advisoryMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/ vendor-advisoryMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/
- https://marc.info/?l=xerces-c-users&m=157653840106914&w=2 Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1311
- https://www.cve.org/CVERecord?id=CVE-2018-1311
- https://www.debian.org/security/2020/dsa-4814 vendor-advisoryThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
Change history (0)
No recorded changes yet.