CVE-2020-14338
published 2020-09-17CVE-2020-14338: A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.29%
67.0th percentile
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | xerces | < 2.12.0 | 2.12.0 |
| redhat | xerces | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
ghsa5.3MEDIUM
osv5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Input Validation in Xerces
ghsa·2022-02-15·CVSS 5.3
CVE-2020-14338 [MEDIUM] CWE-20 Improper Input Validation in Xerces
Improper Input Validation in Xerces
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. All xerces jboss versions before 2.12.0.SP3.
OSV
Improper Input Validation in Xerces
osv·2022-02-15·CVSS 5.3
CVE-2020-14338 [MEDIUM] Improper Input Validation in Xerces
Improper Input Validation in Xerces
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. All xerces jboss versions before 2.12.0.SP3.
Red Hat
wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl
vendor_redhat·2020-08-27·CVSS 5.3
CVE-2020-14338 [MEDIUM] CWE-20 wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl
wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipulate the validation process in certain cases. This issue is the same flaw as CVE-2020-14621, which affected OpenJDK, and uses a similar code. This flaw affects all Xerces JBoss versions before 2.12.0.SP3.
A flaw was found in Wildfly's implementation of Xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. This flaw allows a specially-crafted XML file to manipul
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14338 wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl
bugzilla·2020-07-23·CVSS 5.3
CVE-2020-14338 [MEDIUM] CVE-2020-14338 wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl
CVE-2020-14338 wildfly: XML validation manipulation due to incomplete application of use-grammar-pool-only in xercesImpl
A flaw was found in Wildfly's implementation of xerces, specifically in the way the XMLSchemaValidator class in the JAXP component of Wildfly enforced the "use-grammar-pool-only" feature. A specially-crafted XML file could possibly use this flaw to manipulate with the validation process in certain cases. This is the same flaw as CVE-2020-14621, which affected OpenJDK, which uses similar code.
Discussion:
*** Bug 1860076 has been marked as a duplicate of this bug. ***
---
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss Enterprise Application Platform 5
* Red Hat JBoss Enterprise Application Platform 6
* Red Hat JBoss Da
Bugzilla
CVE-2018-14338 exiv2: buffer overflow in samples/geotag.cpp
bugzilla·2018-07-27·CVSS 8.1
CVE-2018-14338 [HIGH] CVE-2018-14338 exiv2: buffer overflow in samples/geotag.cpp
CVE-2018-14338 exiv2: buffer overflow in samples/geotag.cpp
A flaw was found in Exiv2 0.26. The samples/geotag.cpp in the example code misuses the realpath function on POSIX platforms (other than Apple platforms) where glibc is not used, possibly leading to a buffer overflow.
References:
https://github.com/Exiv2/exiv2/issues/382
Discussion:
Created exiv2 tracking bugs for this issue:
Affects: fedora-all [bug 1609397]
---
We don't ship this. Additionally, this is should not be a problem for us, as we use glibc and realpath() should allocate the buffer there.
---
Statement:
This issue did not affect the versions of exiv2 as shipped with Red Hat Enterprise Linux 6 and 7.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1577 h
https://bugzilla.redhat.com/show_bug.cgi?id=1860054https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103%40%3Cj-users.xerces.apache.org%3Ehttps://bugzilla.redhat.com/show_bug.cgi?id=1860054https://lists.apache.org/thread.html/rf96c5afb26b596b4b97883aa90b6c0b0fc4c26aaeea7123c21912103%40%3Cj-users.xerces.apache.org%3E
2020-09-17
Published