Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3192

Опубликовано: 12 июл. 2016
Источник: debian
EPSS Низкий

Описание

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libspring-javafixed4.1.9-1package
libspring-javano-dsawheezypackage

Примечания

  • https://pivotal.io/security/cve-2015-3192

  • https://jira.spring.io/browse/SPR-13136

EPSS

Процентиль: 80%
0.01378
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 9 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.3
redhat
больше 10 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.5
nvd
больше 9 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.5
github
около 7 лет назад

Pivotal Spring Framework DoS Attack with XML Input

EPSS

Процентиль: 80%
0.01378
Низкий