CVE-2008-4482

Publication date 8 October 2008

Last updated 24 July 2024


Ubuntu priority

The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML schema definition with a large maxOccurs value, which triggers excessive memory consumption during validation of an XML file.

Read the notes from the security team

Status

Package Ubuntu Release Status
xerces-c2 9.10 karmic Ignored
9.04 jaunty Ignored
8.10 intrepid Ignored
8.04 LTS hardy Not in release
7.10 gutsy Not in release
7.04 feisty Not in release
6.06 LTS dapper Not in release

Notes


mdeslaur

debian is not fixing this, let's ignore it also