Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3243

Опубликовано: 22 апр. 2014
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity references.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6SOAPpyWill not fix
Red Hat Enterprise Linux 7SOAPpyWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-776
https://bugzilla.redhat.com/show_bug.cgi?id=1094620SOAPpy: XML entity expansion (billion laughs) flaw

EPSS

Процентиль: 73%
0.00755
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity references.

nvd
больше 11 лет назад

SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted SOAP request containing a large number of nested entity references.

debian
больше 11 лет назад

SOAPpy 0.12.5 does not properly detect recursion during entity expansi ...

github
больше 3 лет назад

SOAPpy vulnerable to XXE attacks

EPSS

Процентиль: 73%
0.00755
Низкий

5 Medium

CVSS2