Описание
SilverStripe framework XML Quadratic Blowup Attack
A low level vulnerability has been found in the SilverStripe framework, where the Quadratic Blowup Attack could potentially be exploited to affect the performance of a site.
See http://mashable.com/2014/08/06/wordpress-xml-blowup-dos/ for a writeup.
Ссылки
- https://github.com/silverstripe/silverstripe-framework/commit/7f983c2bae1dc78ca7217e9af364b2fb71dcefe8
- https://github.com/FriendsOfPHP/security-advisories/blob/master/silverstripe/framework/SS-2014-017-1.yaml
- https://www.silverstripe.org/software/download/security-releases/ss-2014-017-xml-quadratic-blowup-attack
Пакеты
Наименование
silverstripe/framework
composer
Затронутые версииВерсия исправления
<= 3.1.11
3.1.12
5.3 Medium
CVSS3
Дефекты
CWE-400
CWE-776
5.3 Medium
CVSS3
Дефекты
CWE-400
CWE-776