Novell Home

CVE-2009-1885

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2009-1885 at MITRE

Description

Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.

NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)

Novell/SUSE information

Novell Bugzilla entry: 530708

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SLES SDK 9 for IBM S/390 and IBM zSeries
SLES SDK 9 for IBM iSeries and IBM pSeries
SLES SDK 9 for IBM zSeries
SLES SDK 9 for IPF
SLES SDK 9 for X86-64
SLES SDK 9 for x86
  • Xerces-c >= 2.5.0-32.4
  • Xerces-c-devel >= 2.5.0-32.4
core9.x86
core9.s390x
core9.s390
core9.ia64
core9.x86-64
core9.ppc
YOU Patch Nr: 12475
openSUSE 10.3
  • Xerces-c >= 2.7.0-75.2
  • libXerces-c-27 >= 2.7.0-75.2
  • libXerces-c-devel >= 2.7.0-75.2

© 2012 Novell