USN-5293-2: c3p0 vulnerability
22 February 2022
c3p0 could be made to crash if it opened a specially crafted file.
Releases
Packages
- c3p0 - JDBC Connection pooling library
Details
USN-5293-1 fixed a vulnerability in c3p0.
This update provides the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
Aaron Massey discovered that c3p0 could be made to crash when
parsing certain input. An attacker able to modify the application's
XML configuration file could cause a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
libc3p0-java
-
0.9.1.2-9+deb8u1ubuntu0.16.04.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-5293-1: libc3p0-java, c3p0, libc3p0-java-doc