c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Mchange
Subscribe
|
C3p0
Subscribe
|
|
Oracle
Subscribe
|
Communications Ip Service Activator
Subscribe
Communications Session Route Manager
Subscribe
Documaker
Subscribe
Enterprise Manager Base Platform
Subscribe
Enterprise Manager Ops Center
Subscribe
Flexcube Private Banking
Subscribe
Hyperion Infrastructure Technology
Subscribe
Retail Xstore Point Of Service
Subscribe
Webcenter Sites
Subscribe
|
|
Redhat
Subscribe
|
Jboss Fuse
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0409 | c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration. |
Github GHSA |
GHSA-84p2-vf58-xhxv | Billion laughs attack in c3p0 |
Ubuntu USN |
USN-5293-1 | c3p0 vulnerability |
Ubuntu USN |
USN-5293-2 | c3p0 vulnerability |
Ubuntu USN |
USN-7571-1 | c3p0 vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-04T19:54:53.546Z
Reserved: 2019-01-04T00:00:00
Link: CVE-2019-5427
No data.
Status : Analyzed
Published: 2019-04-22T21:29:00.523
Modified: 2025-09-05T17:23:58.510
Link: CVE-2019-5427
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA
Ubuntu USN