CVE-2013-5823

EPSS 5.8%

Apache XML Security For Java vulnerable to Infinite Loop

發布日:2022/5/14修改日:2026/2/4

描述

Affected versions of xmlsec are subject to a denial of service vulnerability. Should a user check the signature of a message larger than 512 MB, the method `expandSize(int newPos)` of class `org.apache.xml.security.utils.UnsyncByteArrayOutputStream` goes in an endless loop. A remote attacker could use this flaw to supply crafted XML that would lead to a denial of service.

受影響套件(1)

參考連結(11)