Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 7: MGASA-2020-0051 Critical: c3p0 XML External Entity Issue

mageia
Calendar Grey January 28, 2020
Dist Mageia Esm H88
The latest c3p0 package updates target XML handling flaws in Mageia. Essential information within.
An XML external entity processing vulnerability was found in extractXmlConfigFromInputStream function in c3p0 (CVE-2018-20433)

Summary

An XML external entity processing vulnerability was found in extractXmlConfigFromInputStream function in c3p0 (CVE-2018-20433).
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration (CVE-2019-5427).

References

- https://bugs.mageia.org/show_bug.cgi?id=25906

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/BFIVX6HOVNLAM7W3SUAMHYRNLCVQSAWR/

- https://www.cve.org/CVERecord?id=CVE-2018-20433

- https://www.cve.org/CVERecord?id=CVE-2019-5427

Resolution

SRPMS

- 7/core/c3p0-0.9.5.4-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 28 Jan 2020
URL: https://advisories.mageia.org/MGASA-2020-0051.html
Type: security
CVE: CVE-2018-20433, CVE-2019-5427

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here