Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8gwc-x7mg-7p7p

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью

Описание

Apache XML Security For Java vulnerable to Infinite Loop

Affected versions of xmlsec are subject to a denial of service vulnerability. Should a user check the signature of a message larger than 512 MB, the method expandSize(int newPos) of class org.apache.xml.security.utils.UnsyncByteArrayOutputStream goes in an endless loop. A remote attacker could use this flaw to supply crafted XML that would lead to a denial of service.

Пакеты

Наименование

org.apache.santuario:xmlsec

maven
Затронутые версииВерсия исправления

>= 1.4.0, < 1.4.8

1.4.8

Наименование

org.apache.santuario:xmlsec

maven
Затронутые версииВерсия исправления

>= 1.5.0, < 1.5.3

1.5.3

EPSS

Процентиль: 89%
0.05067
Низкий

Связанные уязвимости

ubuntu
почти 12 лет назад

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via unknown vectors related to Security.

redhat
почти 12 лет назад

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via unknown vectors related to Security.

nvd
почти 12 лет назад

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect availability via unknown vectors related to Security.

debian
почти 12 лет назад

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE ...

oracle-oval
почти 12 лет назад

ELSA-2013-1505: java-1.6.0-openjdk security update (IMPORTANT)

EPSS

Процентиль: 89%
0.05067
Низкий