VDB

GCVE-110-MAGEIA-2020-51

GCVE-110-MAGEIA-2020-51
Advisory Published
Vulnetix · Advisory published January 28, 2020
An XML external entity processing vulnerability was found in extractXmlConfigFromInputStream function in c3p0 (CVE-2018-20433). c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration (CVE-2019-5427).

Affected Products

VendorProductVersionsPlatforms
Mageiarapid-photo-downloader0.9.18-1.1.mga7 (unaffected), 0 (affected)
Mageiapython-colour0.1.5-1.mga7 (unaffected), 0 (affected)
Mageiapython-tenacity0 (affected), 5.1.1-1.mga7 (unaffected)
Mageiac3p00 (affected), 0.9.5.4-1.mga7 (unaffected), 0 (affected), 0.9.5.4-1.mga7 (unaffected)

Browse GCVE Records

75,726 records in the GCVE database · Updated August 1, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›