imPC@ndo IT

Tracker / CVE-2009-2625

CVE-2009-2625

Medium 5.0

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

Affected products and versions

apache xerces2_java
canonical ubuntu_linux
debian debian_linux
fedoraproject fedora
opensuse opensuse
oracle jdk
oracle primavera_p6_enterprise_project_portfolio_management
oracle primavera_web_services
suse linux_enterprise_server

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References