Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0851

Опубликовано: 21 июл. 2015
Источник: redhat
CVSS2: 5

Описание

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6xmltoolingAffected
Red Hat JBoss BRMS 6xmltoolingAffected
Red Hat JBoss Data Grid 6xmltoolingAffected
Red Hat JBoss Data Virtualization 6xmltoolingAffected
Red Hat JBoss Enterprise Application Platform 6xmltoolingAffected
Red Hat JBoss Enterprise Web Server 1fuse-6.0Affected
Red Hat JBoss Enterprise Web Server 1fuse-esb-7.1Affected
Red Hat JBoss Enterprise Web Server 1fuse-othersAffected
Red Hat JBoss Fuse Service Works 6xmltoolingAffected
Red Hat JBoss Operations Network 3xmltoolingAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1248504xmltooling: incorrect processing of well-formed but invalid XML

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.

nvd
больше 10 лет назад

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.

debian
больше 10 лет назад

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Servic ...

github
больше 3 лет назад

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.

5 Medium

CVSS2