CVE-2019-5427
Published: 22 April 2019
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
Priority
CVSS 3 base score: 7.5
Status
Package | Release | Status |
---|---|---|
c3p0 Launchpad, Ubuntu, Debian |
bionic |
Released
(0.9.1.2-9+deb8u1ubuntu0.18.04.1)
|
cosmic |
Ignored
(reached end-of-life)
|
|
disco |
Ignored
(reached end-of-life)
|
|
eoan |
Ignored
(reached end-of-life)
|
|
focal |
Released
(0.9.1.2-10ubuntu0.20.04.1)
|
|
groovy |
Ignored
(reached end-of-life)
|
|
hirsute |
Ignored
(reached end-of-life)
|
|
impish |
Released
(0.9.1.2-10ubuntu0.21.10.1)
|
|
jammy |
Needed
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
(trusty was needs-triage)
|
|
upstream |
Released
(0.9.5.4)
|
|
xenial |
Ignored
(end of standard support, was needed)
|