CVE-2008-4482: Input Validation
Published Oct 8, 2008
·Updated
The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML schema definition with a large maxOccurs value, which triggers excessive memory consumption during validation of an XML file.
Affected Software
18 affected components
Apache Xerces-c\+\+=1.5.0
Apache Xerces-c\+\+=1.6.0
Apache Xerces-c\+\+=2.0.0
Apache Xerces-c\+\+=1.7.0
Apache Xerces-c\+\+=2.6.0
Apache Xerces-c\+\+=1.1.0
Apache Xerces-c\+\+=1.0.0
Apache Xerces-c\+\+=2.5.0
Apache Xerces-c\+\+=2.4.0
Apache Xerces-c\+\+=2.2.0
Apache Xerces-c\+\+=2.7.0
Apache Xerces-c\+\+=1.3.0
Apache Xerces-c\+\+=1.2.0
Apache Xerces-c\+\+=1.4.0
Apache Xerces-c\+\+=2.1.0
Apache Xerces-c\+\+=1.0.1
Apache Xerces-c\+\+<=2.8.0
Apache Xerces-c\+\+=2.3.0
Remediation
Patch Available
Event History
Oct 8, 2008
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4482?
CVE-2008-4482 has a high severity rating due to the potential for denial of service attacks.
2
How do I fix CVE-2008-4482?
To fix CVE-2008-4482, upgrade your Xerces-C++ library to version 3.0.0 or later.
3
What kind of attack does CVE-2008-4482 enable?
CVE-2008-4482 enables context-dependent denial of service attacks by causing stack consumption and crashes.
4
Which versions of Xerces-C++ are affected by CVE-2008-4482?
CVE-2008-4482 affects all versions of Xerces-C++ before 3.0.0.
5
What is the impact of CVE-2008-4482 on my system?
The impact of CVE-2008-4482 on your system includes excessive memory consumption and application crashes during XML validation.