CVE Vulnerabilities

CVE-2009-2625

Published: Aug 06, 2009 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

Affected Software

Name Vendor Start Version End Version
Jdk Oracle 1.5.0 (including) 1.5.0 (including)
Jdk Oracle 1.5.0-update1 (including) 1.5.0-update1 (including)
Jdk Oracle 1.5.0-update10 (including) 1.5.0-update10 (including)
Jdk Oracle 1.5.0-update11 (including) 1.5.0-update11 (including)
Jdk Oracle 1.5.0-update12 (including) 1.5.0-update12 (including)
Jdk Oracle 1.5.0-update13 (including) 1.5.0-update13 (including)
Jdk Oracle 1.5.0-update14 (including) 1.5.0-update14 (including)
Jdk Oracle 1.5.0-update15 (including) 1.5.0-update15 (including)
Jdk Oracle 1.5.0-update16 (including) 1.5.0-update16 (including)
Jdk Oracle 1.5.0-update17 (including) 1.5.0-update17 (including)
Jdk Oracle 1.5.0-update18 (including) 1.5.0-update18 (including)
Jdk Oracle 1.5.0-update19 (including) 1.5.0-update19 (including)
Jdk Oracle 1.5.0-update2 (including) 1.5.0-update2 (including)
Jdk Oracle 1.5.0-update3 (including) 1.5.0-update3 (including)
Jdk Oracle 1.5.0-update4 (including) 1.5.0-update4 (including)
Jdk Oracle 1.5.0-update5 (including) 1.5.0-update5 (including)
Jdk Oracle 1.5.0-update6 (including) 1.5.0-update6 (including)
Jdk Oracle 1.5.0-update7 (including) 1.5.0-update7 (including)
Jdk Oracle 1.5.0-update8 (including) 1.5.0-update8 (including)
Jdk Oracle 1.5.0-update9 (including) 1.5.0-update9 (including)
Jdk Oracle 1.6.0 (including) 1.6.0 (including)
Jdk Oracle 1.6.0-update1 (including) 1.6.0-update1 (including)
Jdk Oracle 1.6.0-update10 (including) 1.6.0-update10 (including)
Jdk Oracle 1.6.0-update11 (including) 1.6.0-update11 (including)
Jdk Oracle 1.6.0-update12 (including) 1.6.0-update12 (including)
Jdk Oracle 1.6.0-update13 (including) 1.6.0-update13 (including)
Jdk Oracle 1.6.0-update14 (including) 1.6.0-update14 (including)
Jdk Oracle 1.6.0-update2 (including) 1.6.0-update2 (including)
Jdk Oracle 1.6.0-update3 (including) 1.6.0-update3 (including)
Jdk Oracle 1.6.0-update4 (including) 1.6.0-update4 (including)
Jdk Oracle 1.6.0-update5 (including) 1.6.0-update5 (including)
Jdk Oracle 1.6.0-update6 (including) 1.6.0-update6 (including)
Jdk Oracle 1.6.0-update7 (including) 1.6.0-update7 (including)
Expat Ubuntu dapper *
Expat Ubuntu devel *
Expat Ubuntu hardy *
Expat Ubuntu intrepid *
Expat Ubuntu jaunty *
Expat Ubuntu karmic *
Expat Ubuntu lucid *
Expat Ubuntu maverick *
Expat Ubuntu upstream *
Openjdk-6 Ubuntu hardy *
Openjdk-6 Ubuntu intrepid *
Openjdk-6 Ubuntu jaunty *
Openjdk-6 Ubuntu upstream *
Sun-java5 Ubuntu dapper *
Sun-java5 Ubuntu gutsy *
Sun-java5 Ubuntu intrepid *
Sun-java5 Ubuntu jaunty *
Sun-java5 Ubuntu upstream *
Sun-java6 Ubuntu hardy *
Sun-java6 Ubuntu intrepid *
Sun-java6 Ubuntu jaunty *
Sun-java6 Ubuntu karmic *
Sun-java6 Ubuntu lucid *
Sun-java6 Ubuntu upstream *
Extras for RHEL 3 RedHat java-1.4.2-ibm-0:1.4.2.13.1-1jpp.1.el3 *
Extras for RHEL 4 RedHat java-1.5.0-sun-0:1.5.0.20-1jpp.1.el4 *
Extras for RHEL 4 RedHat java-1.6.0-sun-1:1.6.0.15-1jpp.1.el4 *
Extras for RHEL 4 RedHat java-1.5.0-ibm-1:1.5.0.10-1jpp.4.el4 *
Extras for RHEL 4 RedHat java-1.4.2-ibm-0:1.4.2.13.1-1jpp.1.el4 *
Extras for RHEL 4 RedHat java-1.6.0-ibm-1:1.6.0.6-1jpp.3.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat glassfish-javamail-0:1.4.2-0jpp.ep1.5.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat glassfish-jsf-0:1.2_13-2.1.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat hibernate3-1:3.2.4-1.SP1_CP09.0jpp.ep1.1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat hibernate3-annotations-0:3.3.1-1.11.GA_CP02.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat hibernate3-entitymanager-0:3.3.2-2.5.GA_CP01.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jacorb-0:2.3.0-1jpp.ep1.9.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jakarta-commons-logging-jboss-0:1.1-9.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-aop-0:1.5.5-3.CP04.2.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jbossas-0:4.2.0-5.GA_CP08.5.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-common-0:1.2.1-0jpp.ep1.3.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-remoting-0:2.2.3-3.SP1.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-seam-0:1.2.1-1.ep1.22.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jbossts-1:4.2.3-1.SP5_CP08.1jpp.ep1.1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jbossweb-0:2.0.0-6.CP12.0jpp.ep1.2.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jcommon-0:1.0.16-1.1.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jfreechart-0:1.0.13-2.3.1.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jgroups-1:2.4.7-1.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat quartz-0:1.5.2-1jpp.patch01.ep1.4.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat rh-eap-docs-0:4.2.0-6.GA_CP08.ep1.3.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat xerces-j2-0:2.7.1-9jpp.4.patch_02.1.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat xml-security-0:1.3.0-1.3.patch01.ep1.2.el4 *
JBEAP 4.2.0 for RHEL 5 RedHat glassfish-jsf-0:1.2_13-2.1.ep1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat hibernate3-1:3.2.4-1.SP1_CP09.0jpp.ep1.2.4.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat hibernate3-annotations-0:3.3.1-1.11GA_CP02.ep1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat hibernate3-entitymanager-0:3.3.2-2.5.1.ep1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jacorb-0:2.3.0-1jpp.ep1.9.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-aop-0:1.5.5-3.CP04.2.ep1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jbossas-0:4.2.0-5.GA_CP08.5.2.ep1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-common-0:1.2.1-0jpp.ep1.3.el5.1 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-remoting-0:2.2.3-3.SP1.ep1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-seam-0:1.2.1-1.ep1.14.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jbossts-1:4.2.3-1.SP5_CP08.1jpp.ep1.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jbossweb-0:2.0.0-6.CP12.0jpp.ep1.2.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jcommon-0:1.0.16-1.1.ep1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jfreechart-0:1.0.13-2.3.1.ep1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jgroups-1:2.4.7-1.ep1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat quartz-0:1.5.2-1jpp.patch01.ep1.4.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat rh-eap-docs-0:4.2.0-6.GA_CP08.ep1.3.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat xml-security-0:1.3.0-1.3.patch01.ep1.2.1.el5 *
Red Hat Enterprise Linux 5 RedHat java-1.6.0-openjdk-1:1.6.0.0-1.2.b09.el5 *
Red Hat Enterprise Linux 5 RedHat xerces-j2-0:2.7.1-7jpp.2.el5_4.2 *
Red Hat Enterprise Linux 6 RedHat xerces-j2-0:2.7.1-12.6.el6_0 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat glassfish-javamail-0:1.4.2-0jpp.ep1.5.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat glassfish-jaxb-0:2.1.4-1.12.patch03.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat glassfish-jsf-0:1.2_13-2.1.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat hibernate3-1:3.2.4-1.SP1_CP09.0jpp.ep1.1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat hibernate3-annotations-0:3.3.1-1.11.GA_CP02.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat hibernate3-entitymanager-0:3.3.2-2.5.GA_CP01.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jacorb-0:2.3.0-1jpp.ep1.9.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jakarta-commons-logging-jboss-0:1.1-9.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-aop-0:1.5.5-3.CP04.2.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossas-0:4.3.0-6.GA_CP07.4.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-common-0:1.2.1-0jpp.ep1.3.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-messaging-0:1.4.0-3.SP3_CP09.4.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-remoting-0:2.2.3-3.SP1.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.18.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-seam2-0:2.0.2.FP-1.ep1.21.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossts-1:4.2.3-1.SP5_CP08.1jpp.ep1.1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossweb-0:2.0.0-6.CP12.0jpp.ep1.2.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossws-0:2.0.1-4.SP2_CP07.2.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossws-common-0:1.0.0-2.GA_CP05.1.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossws-framework-0:2.0.1-1.GA_CP05.1.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jcommon-0:1.0.16-1.1.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jfreechart-0:1.0.13-2.3.1.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jgroups-1:2.4.7-1.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat quartz-0:1.5.2-1jpp.patch01.ep1.4.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat rh-eap-docs-0:4.3.0-6.GA_CP07.ep1.3.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat xerces-j2-0:2.7.1-9jpp.4.patch_02.1.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat xml-security-0:1.3.0-1.3.patch01.ep1.2.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat glassfish-jaxb-0:2.1.4-1.12.patch03.1.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat glassfish-jsf-0:1.2_13-2.1.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat hibernate3-1:3.2.4-1.SP1_CP09.0jpp.ep1.2.4.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat hibernate3-annotations-0:3.3.1-1.11GA_CP02.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat hibernate3-entitymanager-0:3.3.2-2.5.1.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jacorb-0:2.3.0-1jpp.ep1.9.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-aop-0:1.5.5-3.CP04.2.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossas-0:4.3.0-6.GA_CP07.4.2.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-common-0:1.2.1-0jpp.ep1.3.el5.1 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-messaging-0:1.4.0-3.SP3_CP09.4.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-remoting-0:2.2.3-3.SP1.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.12.el5.1 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-seam2-0:2.0.2.FP-1.ep1.18.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossts-1:4.2.3-1.SP5_CP08.1jpp.ep1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossweb-0:2.0.0-6.CP12.0jpp.ep1.2.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossws-0:2.0.1-4.SP2_CP07.2.1.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossws-common-0:1.0.0-2.GA_CP05.1.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossws-framework-0:2.0.1-1.GA_CP05.1.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jcommon-0:1.0.16-1.1.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jfreechart-0:1.0.13-2.3.1.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jgroups-1:2.4.7-1.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat quartz-0:1.5.2-1jpp.patch01.ep1.4.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat rh-eap-docs-0:4.3.0-6.GA_CP07.ep1.3.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat xml-security-0:1.3.0-1.3.patch01.ep1.2.1.el5 *
Red Hat JBoss Operations Network 3.1 RedHat *
Red Hat JBoss Portal 5.2 RedHat *
Red Hat JBoss Web Framework Kit 2.2 RedHat *
Red Hat Network Satellite Server v 5.1 RedHat java-1.5.0-sun-0:1.5.0.22-1jpp.1.el4 *
Red Hat Network Satellite Server v 5.3 RedHat java-1.6.0-ibm-1:1.6.0.7-1jpp.3.el4 *
RHEL 4 for SAP RedHat java-1.4.2-ibm-0:1.4.2.13.2.sap-1jpp.4.el4_8 *
RHEL 5 for SAP RedHat java-1.4.2-ibm-0:1.4.2.13.2.sap-1jpp.4.el5_3 *
RHEV Manager version 3.0 RedHat jasperreports-server-pro-0:4.7.1-2.el6ev *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.5.0-sun-0:1.5.0.20-1jpp.1.el5 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.6.0-sun-1:1.6.0.15-1jpp.1.el5 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.5.0-ibm-1:1.5.0.10-1jpp.4.el5 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.4.2-ibm-0:1.4.2.13.1-1jpp.1.el5 *
Supplementary for Red Hat Enterprise Linux 5 RedHat java-1.6.0-ibm-1:1.6.0.6-1jpp.3.el5 *

References