CVE-2019-5427

NameCVE-2019-5427
Descriptionc3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs927936

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
c3p0 (PTS)jessie, jessie (lts)0.9.1.2-9+deb8u1vulnerable
stretch0.9.1.2-9+deb9u1vulnerable
sid, trixie, buster, bullseye, bookworm0.9.1.2-10vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
c3p0sourcewheezy(unfixed)end-of-life
c3p0source(unstable)(unfixed)low927936

Notes

[bookworm] - c3p0 <no-dsa> (Minor issue)
[bullseye] - c3p0 <no-dsa> (Minor issue)
[buster] - c3p0 <no-dsa> (Minor issue)
[stretch] - c3p0 <no-dsa> (Minor issue)
[jessie] - c3p0 <no-dsa> (Minor issue)
https://hackerone.com/reports/509315
Fixed by: https://github.com/swaldman/c3p0/commit/f38f27635c384806c2a9d6500d80183d9f09d78b

Search for package or bug name: Reporting problems