Lucene search

K
cveRedhatCVE-2013-4517
HistoryJan 11, 2014 - 1:55 a.m.

CVE-2013-4517

2014-01-1101:55:03
CWE-399
redhat
web.nvd.nist.gov
73
2
cve-2013-4517
apache
santuario
xml security
java
denial of service
memory consumption
dtd
signatures

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6

Confidence

High

EPSS

0.068

Percentile

94.0%

Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures.

Affected configurations

Nvd
Node
apachesantuario_xml_security_for_javaRange≀1.5.5
OR
apachesantuario_xml_security_for_javaMatch1.2.0
OR
apachesantuario_xml_security_for_javaMatch1.2.1
OR
apachesantuario_xml_security_for_javaMatch1.3.0
OR
apachesantuario_xml_security_for_javaMatch1.4.0
OR
apachesantuario_xml_security_for_javaMatch1.4.1
OR
apachesantuario_xml_security_for_javaMatch1.4.2
OR
apachesantuario_xml_security_for_javaMatch1.4.3
OR
apachesantuario_xml_security_for_javaMatch1.4.4
OR
apachesantuario_xml_security_for_javaMatch1.4.5
OR
apachesantuario_xml_security_for_javaMatch1.4.6
OR
apachesantuario_xml_security_for_javaMatch1.4.7
OR
apachesantuario_xml_security_for_javaMatch1.4.8
OR
apachesantuario_xml_security_for_javaMatch1.5.0
OR
apachesantuario_xml_security_for_javaMatch1.5.1
OR
apachesantuario_xml_security_for_javaMatch1.5.2
OR
apachesantuario_xml_security_for_javaMatch1.5.3
OR
apachesantuario_xml_security_for_javaMatch1.5.4
VendorProductVersionCPE
apachesantuario_xml_security_for_java*cpe:2.3:a:apache:santuario_xml_security_for_java:*:*:*:*:*:*:*:*
apachesantuario_xml_security_for_java1.2.0cpe:2.3:a:apache:santuario_xml_security_for_java:1.2.0:*:*:*:*:*:*:*
apachesantuario_xml_security_for_java1.2.1cpe:2.3:a:apache:santuario_xml_security_for_java:1.2.1:*:*:*:*:*:*:*
apachesantuario_xml_security_for_java1.3.0cpe:2.3:a:apache:santuario_xml_security_for_java:1.3.0:*:*:*:*:*:*:*
apachesantuario_xml_security_for_java1.4.0cpe:2.3:a:apache:santuario_xml_security_for_java:1.4.0:*:*:*:*:*:*:*
apachesantuario_xml_security_for_java1.4.1cpe:2.3:a:apache:santuario_xml_security_for_java:1.4.1:*:*:*:*:*:*:*
apachesantuario_xml_security_for_java1.4.2cpe:2.3:a:apache:santuario_xml_security_for_java:1.4.2:*:*:*:*:*:*:*
apachesantuario_xml_security_for_java1.4.3cpe:2.3:a:apache:santuario_xml_security_for_java:1.4.3:*:*:*:*:*:*:*
apachesantuario_xml_security_for_java1.4.4cpe:2.3:a:apache:santuario_xml_security_for_java:1.4.4:*:*:*:*:*:*:*
apachesantuario_xml_security_for_java1.4.5cpe:2.3:a:apache:santuario_xml_security_for_java:1.4.5:*:*:*:*:*:*:*
Rows per page:
1-10 of 181

References

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

AI Score

6

Confidence

High

EPSS

0.068

Percentile

94.0%