Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0851

Опубликовано: 21 июл. 2015
Источник: redhat
CVSS2: 5

Описание

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6xmltoolingAffected
Red Hat JBoss BRMS 6xmltoolingAffected
Red Hat JBoss Data Grid 6xmltoolingAffected
Red Hat JBoss Data Virtualization 6xmltoolingAffected
Red Hat JBoss Enterprise Application Platform 6xmltoolingAffected
Red Hat JBoss Fuse Service Works 6xmltoolingAffected
Red Hat JBoss Operations Network 3xmltoolingAffected
Red Hat JBoss Portal 6xmltoolingAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1248504xmltooling: incorrect processing of well-formed but invalid XML

5 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.

nvd
почти 11 лет назад

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.

debian
почти 11 лет назад

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Servic ...

github
около 4 лет назад

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.

5 Medium

CVSS2