CVE-2013-5823
Apache XML Security For Java vulnerable to Infinite Loop
EPSS 4.7%
Description
Affected versions of xmlsec are subject to a denial of service vulnerability. Should a user check the signature of a message larger than 512 MB, the method `expandSize(int newPos)` of class `org.apache.xml.security.utils.UnsyncByteArrayOutputStream` goes in an endless loop. A remote attacker could use this flaw to supply crafted XML that would lead to a denial of service.
How to fix CVE-2013-5823
To remediate CVE-2013-5823, upgrade the affected package to a fixed version below.
- Maven/org.apache.santuario:xmlsec—upgrade to 1.4.8 or later
Is CVE-2013-5823 being exploited?
Low — EPSS is 4.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 1.4.0, < 1.4.8