USN-5293-1: c3p0 vulnerability
21 February 2022
c3p0 could be made to crash if it opened a specially crafted file.
- c3p0 - JDBC Connection pooling library
Aaron Massey discovered that c3p0 could be made to crash when
parsing certain input. An attacker able to modify the application's
XML configuration file could cause a denial of service.
The problem can be corrected by updating your system to the following package versions:
In general, a standard system update will make all the necessary changes.
- USN-5293-2: c3p0, libc3p0-java-doc, libc3p0-java