Описание
Improper Input Validation in Apache Santuario XML Security
Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2013-4517
- https://github.com/apache/santuario-java/commit/a09b9042f7759d094f2d49f40fc7bcf145164b25
- https://exchange.xforce.ibmcloud.com/vulnerabilities/89891
- https://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3@%3Ccommits.santuario.apache.org%3E
- https://lists.apache.org/thread.html/r1c07a561426ec5579073046ad7f4207cdcef452bb3100abaf908e0cd@%3Ccommits.santuario.apache.org%3E
- https://www.tenable.com/security/tns-2018-15
- http://packetstormsecurity.com/files/124554/Java-XML-Signature-Denial-Of-Service-Attack.html
- http://rhn.redhat.com/errata/RHSA-2014-0170.html
- http://rhn.redhat.com/errata/RHSA-2014-0171.html
- http://rhn.redhat.com/errata/RHSA-2014-0172.html
- http://rhn.redhat.com/errata/RHSA-2014-0195.html
- http://rhn.redhat.com/errata/RHSA-2014-1725.html
- http://rhn.redhat.com/errata/RHSA-2014-1726.html
- http://rhn.redhat.com/errata/RHSA-2014-1727.html
- http://rhn.redhat.com/errata/RHSA-2014-1728.html
- http://rhn.redhat.com/errata/RHSA-2015-0675.html
- http://rhn.redhat.com/errata/RHSA-2015-0850.html
- http://rhn.redhat.com/errata/RHSA-2015-0851.html
- http://santuario.apache.org/secadv.data/cve-2013-4517.txt.asc
- http://seclists.org/fulldisclosure/2013/Dec/169
Пакеты
org.apache.santuario:xmlsec
< 1.5.6
1.5.6
Связанные уязвимости
Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures.
Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures.
Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures.
Apache Santuario XML Security for Java before 1.5.6, when applying Tra ...
Уязвимость платформы для обеспечения стандартов безопасности для XML Apache Santuario XML Security for Java, связанная с ошибками управления ресурсом, позволяющая нарушителю вызвать отказ в обслуживании