First published: Tue Mar 24 2015(Updated: )
internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Debian | =7.1 | |
Fedora | =20 | |
Fedora | =21 | |
Fedora | =22 | |
Apache Xerces-C++ | <=3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-0252 has a severity of medium due to its potential to cause a denial of service.
To fix CVE-2015-0252, upgrade Apache Xerces-C++ to version 3.1.2 or later.
CVE-2015-0252 affects Apache Xerces-C++ versions up to and including 3.1.1, as well as Debian 7.1 and Fedora versions 20, 21, and 22.
CVE-2015-0252 can lead to a denial of service attack resulting in a segmentation fault and crash of the application.
There are no documented workarounds for CVE-2015-0252; the only mitigation involves applying the software update.