CVE-2013-5823
Apache XML Security For Java vulnerable to Infinite Loop
EPSS 4.7%
描述
Affected versions of xmlsec are subject to a denial of service vulnerability. Should a user check the signature of a message larger than 512 MB, the method `expandSize(int newPos)` of class `org.apache.xml.security.utils.UnsyncByteArrayOutputStream` goes in an endless loop. A remote attacker could use this flaw to supply crafted XML that would lead to a denial of service.
如何修補 CVE-2013-5823
要修補 CVE-2013-5823,請將受影響套件升級到下列已修補版本。
- Maven/org.apache.santuario:xmlsec—升級至 1.4.8 或更新版本
CVE-2013-5823 正在被利用嗎?
低 — EPSS 為 4.7%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 1.4.0, < 1.4.8