CVE-2009-1885

NameCVE-2009-1885
DescriptionStack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs540297, 541986

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xerces-c (PTS)buster3.2.2+debian-1+deb10u1fixed
buster (security)3.2.2+debian-1+deb10u2fixed
bullseye3.2.3+debian-3+deb11u1fixed
bookworm3.2.4+debian-1fixed
trixie3.2.4+debian-1.1fixed
sid3.2.4+debian-1.3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xerces-csource(unstable)3.0.1-2low540297
xerces-c2sourcelenny2.8.0-3+lenny1
xerces-c2source(unstable)2.8.0+deb1-2low541986
xerces27source(unstable)(unfixed)

Notes

[etch] - xerces-c <no-dsa> (Minor issue)
[lenny] - xerces-c <no-dsa> (Minor issue)
[etch] - xerces27 <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems