CVE-2009-2625
libxerces2-java - denial of service
EPSS 30.4%
Description
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
How to fix CVE-2009-2625
To remediate CVE-2009-2625, upgrade the affected package to a fixed version below.
- Debian/libxerces2-java—upgrade to 2.9.1-4.1 or later
- Debian/libxerces2-java—upgrade to 2.8.1-1+etch1 or later
- —upgrade to 2.10.0 or later
Is CVE-2009-2625 being exploited?
Moderate — EPSS is 30.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 2.9.1-4.1
- from 0, < 2.8.1-1+etch1
- from 0, < 2.10.0