Vulnerability Description
Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Xerces2 Java | <= 2.11.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2014/07/08/11Mailing List
- https://bugzilla.redhat.com/show_bug.cgi?id=787104Issue Tracking
- https://issues.apache.org/jira/browse/XERCESJ-1685Issue TrackingPatchVendor Advisory
- https://lists.apache.org/thread.html/49dc6702104a86ecbb40292dcd329ce9ae4c32b7473
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e
- https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c24
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12e
- https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d28
- https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133dee
- https://lists.apache.org/thread.html/rea7b831dceeb2a2fa817be6f63b08722042e3647fb
- https://www.oracle.com//security-alerts/cpujul2021.html
- http://www.openwall.com/lists/oss-security/2014/07/08/11Mailing List
- https://bugzilla.redhat.com/show_bug.cgi?id=787104Issue Tracking
- https://issues.apache.org/jira/browse/XERCESJ-1685Issue TrackingPatchVendor Advisory
- https://lists.apache.org/thread.html/49dc6702104a86ecbb40292dcd329ce9ae4c32b7473
FAQ
What is CVE-2012-0881?
CVE-2012-0881 is a vulnerability with a CVSS score of 7.5 (HIGH). Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML service, which triggers hash table collisions.
How severe is CVE-2012-0881?
CVE-2012-0881 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-0881?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Xerces2 Java.