CVE-2018-1311
published 2019-12-18CVE-2018-1311: The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed…
PriorityP349high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
9.50%
94.9th percentile
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | xerces-c | >= 0 < 3.2.3+debian-2 | 3.2.3+debian-2 |
| apache | xerces-c | >= 0 < 3.2.3+debian-2 | 3.2.3+debian-2 |
| apache | xerces-c | >= 0 < 3.2.3+debian-2 | 3.2.3+debian-2 |
| apache | xerces-c | >= 0 < 3.2.3+debian-2 | 3.2.3+debian-2 |
| apache | xerces-c | >= 0 < 3.2.2+debian-1ubuntu0.2 | 3.2.2+debian-1ubuntu0.2 |
| apache | xerces-c | >= 0 < 3.2.3+debian-3ubuntu0.1 | 3.2.3+debian-3ubuntu0.1 |
| apache | xerces-c | >= 0 < 3.1.1-5.1+deb8u4ubuntu0.1~esm2 | 3.1.1-5.1+deb8u4ubuntu0.1~esm2 |
| apache | xerces-c | >= 0 < 3.1.3+debian-1ubuntu0.1~esm2 | 3.1.3+debian-1ubuntu0.1~esm2 |
| apache | xerces-c | >= 0 < 3.1.3+debian-1ubuntu0.1~esm3 | 3.1.3+debian-1ubuntu0.1~esm3 |
| apache | xerces-c | >= 0 < 3.2.0+debian-2ubuntu0.1~esm2 | 3.2.0+debian-2ubuntu0.1~esm2 |
| apache | xerces-c | >= 0 < 3.2.0+debian-2ubuntu0.1~esm3 | 3.2.0+debian-2ubuntu0.1~esm3 |
| apache | xerces-c | >= 0 < 3.2.3+debian-3ubuntu0.1~esm1 | 3.2.3+debian-3ubuntu0.1~esm1 |
| apache | xerces-c | >= 3.0.0 < 3.2.5 | 3.2.5 |
| apache_software_foundation | apache_xerces_c | >= 3.0.0 < 3.2.5 | 3.2.5 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | xerces-c | < xerces-c 3.2.3+debian-2 (bookworm) | xerces-c 3.2.3+debian-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_xerces-c_3.2.3-2_on_cbl_mariner_1.0 | — | — |
| oracle | goldengate | < 21.4.0.0.0 | 21.4.0.0.0 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_oracle8.1HIGH
vendor_redhat8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xerces-c: duplicate CVE to announce correct fixed-in versions
vendor_redhat·2024-02-16·CVSS 8.1
CVE-2024-23807 [HIGH] xerces-c: duplicate CVE to announce correct fixed-in versions
xerces-c: duplicate CVE to announce correct fixed-in versions
The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs.
Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.
Apache issued this CVE to indicate the correct versions of xerces-c, which included the fix for CVE-2018-1311. See the older CVE page for fix status.
Package: xerces-c (Red Hat
Ubuntu
Xerces-C++ vulnerabilities
vendor_ubuntu·2024-01-18·CVSS 8.1
CVE-2018-1311 [HIGH] Xerces-C++ vulnerabilities
Title: Xerces-C++ vulnerabilities
Summary: Several security issues were fixed in Xerces-C++.
It was discovered that Xerces-C++ was not properly handling memory
management operations when parsing XML data containing external DTDs,
which could trigger a use-after-free error. If a user or automated system
were tricked into processing a specially crafted XML document, an attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2018-1311)
It was discovered that Xerces-C++ was not properly performing bounds
checks when processing XML Schema Definition files, which could lead to an
out-of-bounds access via an HTTP request. If a user or automated system
were tricked into processing a specially crafted XSD file
Ubuntu
Xerces-C++ vulnerability
vendor_ubuntu·2024-01-16
CVE-2018-1311 Xerces-C++ vulnerability
Title: Xerces-C++ vulnerability
Summary: Xerces-C++ could be made to crash or run programs if it opened a specially
crafted file.
USN-6579-1 fixed a vulnerability in Xerces-C++. This update provides the
corresponding update for Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 23.04
and Ubuntu 23.10.
Original advisory details:
It was discovered that Xerces-C++ was not properly handling memory
management operations when parsing XML data containing external DTDs,
which could trigger a use-after-free error. If a user or automated system
were tricked into processing a specially crafted XML document, an attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Xerces-C++ vulnerability
vendor_ubuntu·2024-01-11
CVE-2018-1311 Xerces-C++ vulnerability
Title: Xerces-C++ vulnerability
Summary: Xerces-C++ could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that Xerces-C++ was not properly handling memory
management operations when parsing XML data containing external DTDs,
which could trigger a use-after-free error. If a user or automated system
were tricked into processing a specially crafted XML document, an attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle JD Edwards Risk Matrix: Enterprise Infrastructure (Apache Xerces-C++) — CVE-2018-1311
vendor_oracle·2023-04-15·CVSS 8.1
CVE-2018-1311 [HIGH] Oracle Oracle JD Edwards Risk Matrix: Enterprise Infrastructure (Apache Xerces-C++) — CVE-2018-1311
Oracle Oracle JD Edwards Risk Matrix: Enterprise Infrastructure (Apache Xerces-C++) vulnerability
CVE: CVE-2018-1311
CVSS: 8.1
Protocol: JDENET
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Common (Apache Xerces-C) — CVE-2018-1311
vendor_oracle·2022-10-15·CVSS 8.1
CVE-2018-1311 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Common (Apache Xerces-C) — CVE-2018-1311
Oracle Oracle Communications Applications Risk Matrix: Common (Apache Xerces-C) vulnerability
CVE: CVE-2018-1311
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle GoldenGate Risk Matrix: Build Request (Apache Xerces-C++) — CVE-2018-1311
vendor_oracle·2022-01-15·CVSS 8.1
CVE-2018-1311 [HIGH] Oracle Oracle GoldenGate Risk Matrix: Build Request (Apache Xerces-C++) — CVE-2018-1311
Oracle Oracle GoldenGate Risk Matrix: Build Request (Apache Xerces-C++) vulnerability
CVE: CVE-2018-1311
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Red Hat
xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs
vendor_redhat·2019-12-16·CVSS 8.1
CVE-2018-1311 [HIGH] CWE-416 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs
xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
A use-after-free vulnerability was found in xerces-c in the way an XML document is processed via the SAX API. Applications that process XML documents with an external Document Type Definition (DTD) may be vulnerable to this flaw. A remote attacker could exploit this flaw by creating a specially cr
Microsoft
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library
vendor_msrc·2019-12-10·CVSS 8.1
CVE-2018-1311 [HIGH] CWE-416 The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature or via SAX using the XERCES_DISABLE_DTD environment variable.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committ
Debian
CVE-2018-1311: xerces-c - The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error tr...
vendor_debian·2018·CVSS 8.1
CVE-2018-1311 [HIGH] CVE-2018-1311: xerces-c - The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error tr...
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
Scope: local
bookworm: resolved (fixed in 3.2.3+debian-2)
bullseye: resolved (fixed in 3.2.3+debian-2)
forky: resolved (fixed in 3.2.3+debian-2)
sid: resolved (fixed in 3.2.3+debian-2)
trixie: resolved (fixed in 3.2.3+debian-2)
GHSA
GHSA-8582-h585-f568: The Apache Xerces C++ XML parser on versions 3
ghsa_unreviewed·2024-02-29·CVSS 8.1
CVE-2024-23807 [HIGH] CWE-416 GHSA-8582-h585-f568: The Apache Xerces C++ XML parser on versions 3
The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs.
Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.
OSV
CVE-2024-23807: The Apache Xerces C++ XML parser on versions 3
osv·2024-02-29·CVSS 8.1
CVE-2024-23807 [HIGH] CVE-2024-23807: The Apache Xerces C++ XML parser on versions 3
The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended to upgrade to version 3.2.5 which fixes the issue, or mitigate the issue by disabling DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable. This issue has been disclosed before as CVE-2018-1311, but unfortunately that advisory incorrectly stated the issue would be fixed in version 3.2.3 or 3.2.4.
OSV
xerces-c vulnerabilities
osv·2024-01-18·CVSS 8.1
CVE-2018-1311 [HIGH] xerces-c vulnerabilities
xerces-c vulnerabilities
It was discovered that Xerces-C++ was not properly handling memory
management operations when parsing XML data containing external DTDs,
which could trigger a use-after-free error. If a user or automated system
were tricked into processing a specially crafted XML document, an attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2018-1311)
It was discovered that Xerces-C++ was not properly performing bounds
checks when processing XML Schema Definition files, which could lead to an
out-of-bounds access via an HTTP request. If a user or automated system
were tricked into processing a specially crafted XSD file, a remote
attacker could possibly use this issue to cause a denial o
GHSA
GHSA-7rpp-hwhj-9hv8: The Apache Xerces-C 3
ghsa_unreviewed·2022-05-24
CVE-2018-1311 [MEDIUM] CWE-416 GHSA-7rpp-hwhj-9hv8: The Apache Xerces-C 3
The Apache Xerces-C 3.0.0 to 3.2.2 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
OSV
CVE-2018-1311: The Apache Xerces-C 3
osv·2019-12-18·CVSS 8.1
CVE-2018-1311 [HIGH] CVE-2018-1311: The Apache Xerces-C 3
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
No detection rules found.
Bugzilla
CVE-2018-1311 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs [fedora-all]
bugzilla·2020-01-07·CVSS 8.1
CVE-2018-1311 [HIGH] CVE-2018-1311 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs [fedora-all]
CVE-2018-1311 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2018-1311 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs
bugzilla·2020-01-07·CVSS 8.1
CVE-2018-1311 [HIGH] CVE-2018-1311 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs
CVE-2018-1311 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs
XML parser contains a use-after-free error triggered during the scanning of external DTDs. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
External References:
https://marc.info/?l=xerces-c-users&m=157653840106914&w=2
Discussion:
Created xerces-c tracking bugs for this issue:
Affects: epel-6 [bug 1788474]
Affects: epel-8 [bug 1788475]
Affects: fedora-all [bug 1788473]
---
Mitigation:
Disable DTD processing by setting the environment variable `XERCES_DISABLE_DTD=1`. Please note that this feature was introduced in xerces-c upstream version 3.1.4 and is not available in older versions. The
Bugzilla
CVE-2018-1311 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs [epel-8]
bugzilla·2020-01-07·CVSS 8.1
CVE-2018-1311 [HIGH] CVE-2018-1311 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs [epel-8]
CVE-2018-1311 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs [epel-8]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-8.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion
Bugzilla
CVE-2018-1311 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs [epel-6]
bugzilla·2020-01-07·CVSS 8.1
CVE-2018-1311 [HIGH] CVE-2018-1311 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs [epel-6]
CVE-2018-1311 xerces-c: XML parser contains a use-after-free error triggered during the scanning of external DTDs [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion
http://www.openwall.com/lists/oss-security/2024/02/16/1https://access.redhat.com/errata/RHSA-2020:0702https://access.redhat.com/errata/RHSA-2020:0704https://lists.apache.org/thread.html/r48ea463fde218b1e4cc1a1d05770a0cea34de0600b4355315a49226b%40%3Cc-dev.xerces.apache.org%3Ehttps://lists.apache.org/thread.html/r90ec105571622a7dc3a43b846c12732d2e563561dfb2f72941625f35%40%3Cc-users.xerces.apache.org%3Ehttps://lists.apache.org/thread.html/rabbcc0249de1dda70cda96fd9bcff78217be7a57d96e7dcc8cd96646%40%3Cc-users.xerces.apache.org%3Ehttps://lists.apache.org/thread.html/rfeb8abe36bcca91eb603deef49fbbe46870918830a66328a780b8625%40%3Cc-users.xerces.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/12/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2023/12/msg00027.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A6WWL4SWKAVYK6VK5YN7KZP4MZWC7IY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/https://marc.info/?l=xerces-c-users&m=157653840106914&w=2https://www.debian.org/security/2020/dsa-4814https://www.oracle.com/security-alerts/cpujan2022.htmlhttp://www.openwall.com/lists/oss-security/2024/02/16/1https://access.redhat.com/errata/RHSA-2020:0702https://access.redhat.com/errata/RHSA-2020:0704https://lists.apache.org/thread.html/r48ea463fde218b1e4cc1a1d05770a0cea34de0600b4355315a49226b%40%3Cc-dev.xerces.apache.org%3Ehttps://lists.apache.org/thread.html/r90ec105571622a7dc3a43b846c12732d2e563561dfb2f72941625f35%40%3Cc-users.xerces.apache.org%3Ehttps://lists.apache.org/thread.html/rabbcc0249de1dda70cda96fd9bcff78217be7a57d96e7dcc8cd96646%40%3Cc-users.xerces.apache.org%3Ehttps://lists.apache.org/thread.html/rfeb8abe36bcca91eb603deef49fbbe46870918830a66328a780b8625%40%3Cc-users.xerces.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2020/12/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2023/12/msg00027.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A6WWL4SWKAVYK6VK5YN7KZP4MZWC7IY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/https://lists.fedoraproject.org/archives/list/[email protected]/message/AJYZUBGPVWJ7LEHRCMB5XVADQBNGURXD/https://marc.info/?l=xerces-c-users&m=157653840106914&w=2https://www.debian.org/security/2020/dsa-4814https://www.oracle.com/security-alerts/cpujan2022.html
2019-12-18
Published