Vulnerabilidad en Apache Xerces2 Java Parser (CVE-2013-4002)
Gravedad CVSS v2.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
23/07/2013
Última modificación:
11/04/2025
Descripción
XMLscanner.java en Apache Xerces2 Java Parser, en versiones anteriores a la 2.12.0, tal y como se empleó en Java Runtime Environment (JRE) en IBM Java, en versiones 5.0 anteriores a la 5.0 SR16-FP3, 6 anteriores a la 6 SR14, 6.0.1 anteriores a la 6.0.1 SR6 y 7 anteriores a la 7 SR5, así como en Oracle Java SE 7u40 y anteriores, Java SE 6u60 y anteriores, Java SE 5.0u51 y anteriores, JRockit R28.2.8 y anteriores, JRockit R27.7.6 y anteriores, Java SE Embedded 7u40 y anteriores y, posiblemente, otros productos, permite que los atacantes remotos realicen una denegación de servicio (DoS) mediante vectores relacionados con los nombres de atributo XML.
Impacto
Puntuación base 2.0
7.10
Gravedad 2.0
ALTA
Productos y versiones vulnerables
CPE | Desde | Hasta |
---|---|---|
cpe:2.3:a:ibm:java:5.0.0.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:java:5.0.11.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:java:5.0.11.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:java:5.0.11.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:java:5.0.12.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:java:5.0.12.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:java:5.0.12.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:java:5.0.12.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:java:5.0.12.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:java:5.0.12.5:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:java:5.0.13.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:java:5.0.14.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:java:5.0.15.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:java:5.0.16.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:ibm:java:5.0.16.1:*:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00010.html
- http://lists.opensuse.org/opensuse-updates/2013-11/msg00023.html
- http://marc.info/?l=bugtraq&m=138674031212883&w=2
- http://marc.info/?l=bugtraq&m=138674073720143&w=2
- http://rhn.redhat.com/errata/RHSA-2013-1059.html
- http://rhn.redhat.com/errata/RHSA-2013-1060.html
- http://rhn.redhat.com/errata/RHSA-2013-1081.html
- http://rhn.redhat.com/errata/RHSA-2013-1440.html
- http://rhn.redhat.com/errata/RHSA-2013-1447.html
- http://rhn.redhat.com/errata/RHSA-2013-1451.html
- http://rhn.redhat.com/errata/RHSA-2013-1505.html
- http://rhn.redhat.com/errata/RHSA-2014-1818.html
- http://rhn.redhat.com/errata/RHSA-2014-1821.html
- http://rhn.redhat.com/errata/RHSA-2014-1822.html
- http://rhn.redhat.com/errata/RHSA-2014-1823.html
- http://rhn.redhat.com/errata/RHSA-2015-0675.html
- http://rhn.redhat.com/errata/RHSA-2015-0720.html
- http://rhn.redhat.com/errata/RHSA-2015-0765.html
- http://rhn.redhat.com/errata/RHSA-2015-0773.html
- http://secunia.com/advisories/56257
- http://security.gentoo.org/glsa/glsa-201406-32.xml
- http://support.apple.com/kb/HT5982
- http://svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java?r1=965250&r2=1499506&view=patch
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC98015
- http://www-01.ibm.com/support/docview.wss?uid=swg21644197
- http://www-01.ibm.com/support/docview.wss?uid=swg21653371
- http://www-01.ibm.com/support/docview.wss?uid=swg21657539
- http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS13-025/index.html
- http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_ibm_filenet_content_manager_and_ibm_content_foundation_xml_4j_denial_of_service_attack_cve_2013_4002
- http://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_July_2013
- http://www.ibm.com/support/docview.wss?uid=swg21648172
- http://www.securityfocus.com/bid/61310
- http://www.ubuntu.com/usn/USN-2033-1
- http://www.ubuntu.com/usn/USN-2089-1
- https://access.redhat.com/errata/RHSA-2014:0414
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85260
- https://issues.apache.org/jira/browse/XERCESJ-1679
- https://lists.apache.org/thread.html/49dc6702104a86ecbb40292dcd329ce9ae4c32b74733199ecab14a73%40%3Cj-users.xerces.apache.org%3E
- https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
- http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00026.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html
- http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2013-08/msg00003.html
- http://lists.opensuse.org/opensuse-security-announce/2013-11/msg00010.html
- http://lists.opensuse.org/opensuse-updates/2013-11/msg00023.html
- http://marc.info/?l=bugtraq&m=138674031212883&w=2
- http://marc.info/?l=bugtraq&m=138674073720143&w=2
- http://rhn.redhat.com/errata/RHSA-2013-1059.html
- http://rhn.redhat.com/errata/RHSA-2013-1060.html
- http://rhn.redhat.com/errata/RHSA-2013-1081.html
- http://rhn.redhat.com/errata/RHSA-2013-1440.html
- http://rhn.redhat.com/errata/RHSA-2013-1447.html
- http://rhn.redhat.com/errata/RHSA-2013-1451.html
- http://rhn.redhat.com/errata/RHSA-2013-1505.html
- http://rhn.redhat.com/errata/RHSA-2014-1818.html
- http://rhn.redhat.com/errata/RHSA-2014-1821.html
- http://rhn.redhat.com/errata/RHSA-2014-1822.html
- http://rhn.redhat.com/errata/RHSA-2014-1823.html
- http://rhn.redhat.com/errata/RHSA-2015-0675.html
- http://rhn.redhat.com/errata/RHSA-2015-0720.html
- http://rhn.redhat.com/errata/RHSA-2015-0765.html
- http://rhn.redhat.com/errata/RHSA-2015-0773.html
- http://secunia.com/advisories/56257
- http://security.gentoo.org/glsa/glsa-201406-32.xml
- http://support.apple.com/kb/HT5982
- http://svn.apache.org/viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java?r1=965250&r2=1499506&view=patch
- http://www-01.ibm.com/support/docview.wss?uid=swg1IC98015
- http://www-01.ibm.com/support/docview.wss?uid=swg21644197
- http://www-01.ibm.com/support/docview.wss?uid=swg21653371
- http://www-01.ibm.com/support/docview.wss?uid=swg21657539
- http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS13-025/index.html
- http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_ibm_filenet_content_manager_and_ibm_content_foundation_xml_4j_denial_of_service_attack_cve_2013_4002
- http://www.ibm.com/developerworks/java/jdk/alerts/#IBM_Security_Update_July_2013
- http://www.ibm.com/support/docview.wss?uid=swg21648172
- http://www.securityfocus.com/bid/61310
- http://www.ubuntu.com/usn/USN-2033-1
- http://www.ubuntu.com/usn/USN-2089-1
- https://access.redhat.com/errata/RHSA-2014:0414
- https://exchange.xforce.ibmcloud.com/vulnerabilities/85260
- https://issues.apache.org/jira/browse/XERCESJ-1679
- https://lists.apache.org/thread.html/49dc6702104a86ecbb40292dcd329ce9ae4c32b74733199ecab14a73%40%3Cj-users.xerces.apache.org%3E
- https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451%40%3Csolr-user.lucene.apache.org%3E
- https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html