Asymmetric denial of service In org.apache.santuario:xmlsec
Description
Apache XML Security For Java vulnerable to Infinite Loop
Affected versions of xmlsec are subject to a denial of service vulnerability. Should a user check the signature of a message larger than 512 MB, the method expandSize(int newPos) of class org.apache.xml.security.utils.UnsyncByteArrayOutputStream goes in an endless loop. A remote attacker could use this flaw to supply crafted XML that would lead to a denial of service.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 1.4.8, 1.5.3 | ||
rpm rhel5 | 1:1.6.0.0-1.42.1.11.14.el5_10 | ||
rpm rhel6 | 1:1.6.0.0-1.65.1.11.14.el6_4 | ||
rpm rhel5 | 1:1.7.0.45-2.4.3.1.el5_10 | ||
rpm rhel6 | 1:1.7.0.45-2.4.3.2.el6_4 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8.