CVE-2013-4517

Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:xml_security_for_java:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.5.2:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.5.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.4.6:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.4.5:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.4.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.5.3:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.4.7:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.5.0:*:*:*:*:*:*:*
cpe:2.3:a:apache:xml_security_for_java:1.4.8:*:*:*:*:*:*:*

Information

Published : 2014-01-10 17:55

Updated : 2021-09-17 04:15


NVD link : CVE-2013-4517

Mitre link : CVE-2013-4517


JSON object : View

CWE
CWE-399

Resource Management Errors

Advertisement

dedicated server usa

Products Affected

apache

  • xml_security_for_java