[jira] [Commented] (XERCESC-2188) Use-after-free on external DTD scan
"Ilguiz Latypov (Jira)" <[email protected]> Wed, 26 Apr 2023 20:30:00 +0000 (UTC)
| Newsgroups | gmane.text.xml.xerces-c.devel |
|---|---|
| Message-ID | <[email protected]> |
[ https://issues.apache.org/jira/browse/XERCESC-2188?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17716908#comment-17716908 ]
Ilguiz Latypov commented on XERCESC-2188:
-----------------------------------------
Perhaps NVD and scan KBs rely on this ticket's description carrying the "affected versions" field. Adding 3.2.3 and 3.2.4 to it could at least confirm the presence of the weakness for others.
NVD mentions Apache as the CVE Numbering Authority for this issue.
> Use-after-free on external DTD scan
> -----------------------------------
>
> Key: XERCESC-2188
> URL: https://issues.apache.org/jira/browse/XERCESC-2188
> Project: Xerces-C++
> Issue Type: Bug
> Components: Validating Parser (DTD)
> Affects Versions: 3.0.0, 3.0.1, 3.0.2, 3.1.0, 3.1.1, 3.1.2, 3.2.0, 3.1.3, 3.1.4, 3.2.1, 3.2.2
> Reporter: Scott Cantor
> Priority: Major
> Attachments: Apache-496067-disclosure-report.pdf
>
>
> This is a record of an unfixed bug reported in 2018 in the DTD scanner, per the attached PDF, corresponding to CVE-2018-1311.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)