/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2013-5823

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2013-5823

CGA ID

CGA-hrgv-2rpw-7g3v

Summary

Apache XML Security For Java vulnerable to Infinite Loop

Description

Affected versions of xmlsec are subject to a denial of service vulnerability. Should a user check the signature of a message larger than 512 MB, the method expandSize(int newPos) of class org.apache.xml.security.utils.UnsyncByteArrayOutputStream goes in an endless loop. A remote attacker could use this flaw to supply crafted XML that would lead to a denial of service.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images