Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3192

Опубликовано: 12 июл. 2016
Источник: debian
EPSS Низкий

Описание

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libspring-javafixed4.1.9-1package
libspring-javano-dsawheezypackage

Примечания

  • https://pivotal.io/security/cve-2015-3192

  • https://jira.spring.io/browse/SPR-13136

EPSS

Процентиль: 79%
0.01378
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.3
redhat
почти 10 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.5
nvd
почти 9 лет назад

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.

CVSS3: 5.5
github
больше 6 лет назад

Pivotal Spring Framework DoS Attack with XML Input

EPSS

Процентиль: 79%
0.01378
Низкий