CVE-2017-12627: Null Pointer Dereference
Apache Xerces-C XML Parser library is vulnerable to a denial of service, caused by a NULL pointer dereference when processing external DTD paths. A remote attacker could exploit this vulnerability to cause a denial of service.
Other sources
In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12627?
CVE-2017-12627 has been assigned a medium severity level due to its potential for denial of service when processing external DTD paths.
How do I fix CVE-2017-12627?
To fix CVE-2017-12627, update Apache Xerces-C XML Parser to version 3.2.1 or later.
Which versions of Apache Xerces-C are affected by CVE-2017-12627?
Apache Xerces-C XML Parser versions before 3.2.1 are affected by CVE-2017-12627.
Can CVE-2017-12627 be exploited remotely?
Yes, a remote attacker could exploit CVE-2017-12627 to cause a denial of service.
What software products are impacted by CVE-2017-12627?
CVE-2017-12627 impacts IBM Cognos Analytics versions up to 12.0.3 and 11.2.4 FP4, along with all versions of Apache Xerces-C++ before 3.2.1.