CVE-2009-2625
Last modified
CVE-2009-2625 is a vulnerability of currently unknown severity. XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.. EPSS estimates a 30.38% chance of exploitation in the next 30 days.
Description
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Oracle | Jdk | 1.5.0 | — |
| Oracle | Jdk | 1.6.0 | — |
| Fedoraproject | Fedora | 10 | — |
| Fedoraproject | Fedora | 11 | — |
| Opensuse | Opensuse | 11.0 | — |
| Opensuse | Opensuse | 11.1 | — |
| Opensuse | Opensuse | 11.2 | — |
| Suse | Linux Enterprise Server | 9 | — |
| Suse | Linux Enterprise Server | 10 | Sp2 |
| Suse | Linux Enterprise Server | 11 | — |
| Debian | Debian Linux | 4.0 | — |
| Debian | Debian Linux | 5.0 | — |
| Canonical | Ubuntu Linux | 6.06 | — |
| Canonical | Ubuntu Linux | 8.04 | — |
| Canonical | Ubuntu Linux | 8.10 | — |
| Canonical | Ubuntu Linux | 9.04 | — |
| Canonical | Ubuntu Linux | 9.10 | — |
| Oracle | Primavera P6 Enterprise Project Portfolio Management | 6.1 | — |
| Oracle | Primavera P6 Enterprise Project Portfolio Management | 6.2.1 | — |
| Oracle | Primavera P6 Enterprise Project Portfolio Management | 7.0 | — |
| Oracle | Primavera Web Services | 6.2.1 | — |
| Oracle | Primavera Web Services | 7.0 | — |
| Apache | Xerces2 Java | 2.9.1 | — |
References
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=125787273209737&w=2Mailing List, Third Party Advisory
- http://secunia.com/advisories/36162Third Party Advisory
- http://secunia.com/advisories/36176Third Party Advisory
- http://secunia.com/advisories/36180Third Party Advisory
- http://secunia.com/advisories/36199Third Party Advisory
- http://secunia.com/advisories/37300Third Party Advisory
- http://secunia.com/advisories/37460Third Party Advisory
- http://secunia.com/advisories/37671Third Party Advisory
- http://secunia.com/advisories/37754Third Party Advisory
- http://secunia.com/advisories/38231Third Party Advisory
- http://secunia.com/advisories/38342Third Party Advisory
- http://secunia.com/advisories/43300Third Party Advisory
- http://secunia.com/advisories/50549Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1Broken Link, Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-263489-1Broken Link, Patch, Vendor Advisory
- http://www.cert.fi/en/reports/2009/vulnerability2009085.htmlThird Party Advisory
- http://www.codenomicon.com/labs/xml/Third Party Advisory
- http://www.debian.org/security/2010/dsa-1984Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:209Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:108Third Party Advisory
- http://www.networkworld.com/columnists/2009/080509-xml-flaw.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2009/09/06/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/10/22/9Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/10/23/6Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/10/26/3Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1615.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0858.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/507985/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35958Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1022680Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-890-1Third Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA09-294A.htmlThird Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA10-012A.htmlThird Party Advisory, US Government Resource
- http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2009/2543Permissions Required
- http://www.vupen.com/english/advisories/2009/3316Permissions Required
- http://www.vupen.com/english/advisories/2011/0359Permissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=512921Issue Tracking, Third Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.htmlMailing List, Third Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.htmlMailing List, Third Party Advisory
- http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.htmlThird Party Advisory
- http://marc.info/?l=bugtraq&m=125787273209737&w=2Mailing List, Third Party Advisory
- http://secunia.com/advisories/36162Third Party Advisory
- http://secunia.com/advisories/36176Third Party Advisory
- http://secunia.com/advisories/36180Third Party Advisory
- http://secunia.com/advisories/36199Third Party Advisory
- http://secunia.com/advisories/37300Third Party Advisory
- http://secunia.com/advisories/37460Third Party Advisory
- http://secunia.com/advisories/37671Third Party Advisory
- http://secunia.com/advisories/37754Third Party Advisory
- http://secunia.com/advisories/38231Third Party Advisory
- http://secunia.com/advisories/38342Third Party Advisory
- http://secunia.com/advisories/43300Third Party Advisory
- http://secunia.com/advisories/50549Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1Broken Link, Patch
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-263489-1Broken Link, Patch, Vendor Advisory
- http://www.cert.fi/en/reports/2009/vulnerability2009085.htmlThird Party Advisory
- http://www.codenomicon.com/labs/xml/Third Party Advisory
- http://www.debian.org/security/2010/dsa-1984Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:209Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2011:108Third Party Advisory
- http://www.networkworld.com/columnists/2009/080509-xml-flaw.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2009/09/06/1Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/10/22/9Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/10/23/6Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2009/10/26/3Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujan2010-084891.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2009-1615.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0858.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/507985/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35958Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1022680Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-890-1Third Party Advisory
- http://www.us-cert.gov/cas/techalerts/TA09-294A.htmlThird Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA10-012A.htmlThird Party Advisory, US Government Resource
- http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2009/2543Permissions Required
- http://www.vupen.com/english/advisories/2009/3316Permissions Required
- http://www.vupen.com/english/advisories/2011/0359Permissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=512921Issue Tracking, Third Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.htmlMailing List, Third Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.htmlMailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-2625?
How severe is CVE-2009-2625?
How do I fix CVE-2009-2625?
Are you affected by CVE-2009-2625?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
