Package        : c3p0
Version        : 0.9.1.2-9+deb8u1
CVE ID         : CVE-2018-20433
Debian Bug     : 917257

A XML External Entity (XXE) vulnerability was discovered in c3p0, a
library for JDBC connection pooling, that may be used to resolve
information outside of the intended sphere of control.

For Debian 8 "Jessie", this problem has been fixed in version
0.9.1.2-9+deb8u1.

We recommend that you upgrade your c3p0 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-1621-1: c3p0 security update

December 28, 2018
A XML External Entity (XXE) vulnerability was discovered in c3p0, a library for JDBC connection pooling, that may be used to resolve information outside of the intended sphere of c...

Summary

We recommend that you upgrade your c3p0 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : c3p0
Version : 0.9.1.2-9+deb8u1
CVE ID : CVE-2018-20433
Debian Bug : 917257

Related News