Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-2155

Опубликовано: 20 авг. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.8

Описание

Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted length values to the (1) compareBase64StringToRaw, (2) DSIGAlgorithmHandlerDefault, or (3) DSIGAlgorithmHandlerDefault::verify functions.

РелизСтатусПримечание
devel

not-affected

1.6.1-6
lucid

released

1.5.1-3+squeeze2build0.10.04.1
precise

released

1.6.1-1ubuntu0.1
quantal

released

1.6.1-6~build0.12.10.1
raring

released

1.6.1-6~build0.13.04.1
upstream

released

1.6.1-6

Показывать по

Ссылки на источники

EPSS

Процентиль: 81%
0.01566
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

nvd
больше 12 лет назад

Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted length values to the (1) compareBase64StringToRaw, (2) DSIGAlgorithmHandlerDefault, or (3) DSIGAlgorithmHandlerDefault::verify functions.

debian
больше 12 лет назад

Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7. ...

github
больше 3 лет назад

Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted length values to the (1) compareBase64StringToRaw, (2) DSIGAlgorithmHandlerDefault, or (3) DSIGAlgorithmHandlerDefault::verify functions.

EPSS

Процентиль: 81%
0.01566
Низкий

5.8 Medium

CVSS2