yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2017-12627
Component Overview
Vulnerability Overview
Name
CVE-2017-12627
Source
NVD (
link
)
Debian (
link
)
Description
In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.
CWEs
CWE-476
Published Date
Mar 1, 2018
Updated Date
Jun 17, 2026
Workaround
-
Advisories
http://seclists.org/oss-sec/2018/q1/203
Mailing List
http://www.securityfocus.com/bid/103219
VDB Entry
http://xerces.apache.org/xerces-c/secadv/CVE-2017-12627.txt
Vendor Advisory
http://seclists.org/oss-sec/2018/q1/203
Mailing List
http://www.securityfocus.com/bid/103219
VDB Entry
http://xerces.apache.org/xerces-c/secadv/CVE-2017-12627.txt
Vendor Advisory
Analysis
#
Affected Component
Analysis
xerces-c
Exploitable
Vulnerability Ratings
#
9.8
other
7.5
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
xerces
buildroot
2025.02.x
3.2.5
Not Affected
xerces
buildroot
master
3.3.0
Not Affected
xerces-c
yocto
master
3.3.0
Not Affected
xerces-c
yocto
scarthgap
3.2.5
Not Affected