CVE-2015-0252: Input Validation
Published Mar 24, 2015
·Updated
internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.
Affected Software
5 affected components
Debian Debian Linux=7.1
Fedoraproject Fedora=20
Fedoraproject Fedora=21
Fedoraproject Fedora=22
Apache Xerces-c\+\+<=3.1.1
Event History
Mar 24, 2015
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0252?
CVE-2015-0252 has a severity of medium due to its potential to cause a denial of service.
2
How do I fix CVE-2015-0252?
To fix CVE-2015-0252, upgrade Apache Xerces-C++ to version 3.1.2 or later.
3
Which software versions are affected by CVE-2015-0252?
CVE-2015-0252 affects Apache Xerces-C++ versions up to and including 3.1.1, as well as Debian 7.1 and Fedora versions 20, 21, and 22.
4
What kind of attack can CVE-2015-0252 lead to?
CVE-2015-0252 can lead to a denial of service attack resulting in a segmentation fault and crash of the application.
5
Is there a workaround for CVE-2015-0252?
There are no documented workarounds for CVE-2015-0252; the only mitigation involves applying the software update.