The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXML document containing a large number of nested entity references, aka a "billion laughs attack."
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 01:50
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2013-March/099553.html - | |
References | () http://osvdb.org/91439 - | |
References | () http://seclists.org/oss-sec/2013/q1/674 - | |
References | () http://secunia.com/advisories/52659 - | |
References | () http://sourceforge.net/p/opalvoip/code/28856 - Exploit, Patch | |
References | () http://www.ekiga.org/news/2013-02-21/ekiga-4.0.1-stable-available - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/58520 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/82885 - | |
References | () https://www.suse.com/support/update/announcement/2014/suse-su-20140237-1.html - |
Information
Published : 2014-05-23 14:55
Updated : 2024-11-21 01:50
NVD link : CVE-2013-1864
Mitre link : CVE-2013-1864
CVE.ORG link : CVE-2013-1864
JSON object : View
Products Affected
suse
- suse_linux_enterprise_desktop
- suse_linux_enterprise_software_development_kit
ekiga
- ekiga
opalvoip
- portable_tool_library
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer