Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-2154

Опубликовано: 20 авг. 2013
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 7.5

Описание

Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions, probably related to the DSIGReference::getURIBaseTXFM function.

РелизСтатусПримечание
devel

not-affected

1.6.1-6
lucid

released

1.5.1-3+squeeze2build0.10.04.1
precise

released

1.6.1-1ubuntu0.1
quantal

released

1.6.1-6~build0.12.10.1
raring

released

1.6.1-6~build0.13.04.1
upstream

released

1.6.1-6

Показывать по

Ссылки на источники

EPSS

Процентиль: 82%
0.01673
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
больше 12 лет назад

Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions, probably related to the DSIGReference::getURIBaseTXFM function.

debian
больше 12 лет назад

Stack-based buffer overflow in the XML Signature Reference functionali ...

github
больше 3 лет назад

Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions, probably related to the DSIGReference::getURIBaseTXFM function.

EPSS

Процентиль: 82%
0.01673
Низкий

7.5 High

CVSS2