Aaron Massey discovered that c3p0 could be made to crash when parsing certain input. An attacker able to modify the application’s XML configuration file could possibly use this issue to cause a denial of service.
{ "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro", "binaries": [ { "binary_version": "0.9.1.2-9+deb8u1ubuntu0.14.04.1~esm1", "binary_name": "libc3p0-java" } ] }