Description
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0409 | c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration. |
Github GHSA |
GHSA-84p2-vf58-xhxv | Billion laughs attack in c3p0 |
Ubuntu USN |
USN-5293-1 | c3p0 vulnerability |
Ubuntu USN |
USN-5293-2 | c3p0 vulnerability |
Ubuntu USN |
USN-7571-1 | c3p0 vulnerability |
References
History
No history.
Subscriptions
Fedoraproject
Subscribe
Fedora
Subscribe
Mchange
Subscribe
C3p0
Subscribe
Oracle
Subscribe
Communications Ip Service Activator
Subscribe
Communications Session Route Manager
Subscribe
Documaker
Subscribe
Enterprise Manager Base Platform
Subscribe
Enterprise Manager Ops Center
Subscribe
Flexcube Private Banking
Subscribe
Hyperion Infrastructure Technology
Subscribe
Retail Xstore Point Of Service
Subscribe
Webcenter Sites
Subscribe
Redhat
Subscribe
Jboss Fuse
Subscribe
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-04T19:54:53.546Z
Reserved: 2019-01-04T00:00:00.000Z
Link: CVE-2019-5427
No data.
Status : Analyzed
Published: 2019-04-22T21:29:00.523
Modified: 2025-09-05T17:23:58.510
Link: CVE-2019-5427
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA
Ubuntu USN