Lucene search

K
osvGoogleOSV:USN-5293-2
HistoryFeb 22, 2022 - 10:19 a.m.

c3p0 vulnerability

2022-02-2210:19:21
Google
osv.dev
7
usn-5293-1
c3p0
xml config file
vulnerability
denial of service
ubuntu 16.04 esm

EPSS

0.023

Percentile

89.8%

USN-5293-1 fixed a vulnerability in c3p0.
This update provides the corresponding update for Ubuntu 16.04 ESM.

Original advisory details:

Aaron Massey discovered that c3p0 could be made to crash when
parsing certain input. An attacker able to modify the application’s
XML configuration file could cause a denial of service.