Back

HIGH

c3p0: loading XML configuration leads to denial of service

Published Apr 22, 2019

Description

c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.

Affected products

Remediation

Red Hat statement

Red Hat Satellite 6 is not vulnerable to this issue, because the candlepin component who uses the c3p0 jar never passes a XML configuration file to c3p0, even though it includes a vulnerable version of the latter. Since this issue requires a XML files to be loaded by c3p0, an exploitation path doesn't exist.

Weaknesses (1)

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Apr 22, 2019
Updated Aug 4, 2024
Reserved Jan 4, 2019
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 17, 2019
GHSA-84P2-VF58-XHXV