Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-4482
HistoryOct 08, 2008 - 12:00 a.m.

CVE-2008-4482

2008-10-0800:00:00
ubuntu.com
ubuntu.com
12

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.003

Percentile

68.0%

The XML parser in Xerces-C++ before 3.0.0 allows context-dependent
attackers to cause a denial of service (stack consumption and crash) via an
XML schema definition with a large maxOccurs value, which triggers
excessive memory consumption during validation of an XML file.

Notes

Author Note
mdeslaur debian is not fixing this, let’s ignore it also

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

EPSS

0.003

Percentile

68.0%