LWN.net Logo

cxf: denial of service

Package(s):cxf CVE #(s):CVE-2013-2160
Created:August 12, 2013 Updated:August 14, 2013
Description: From the Red Hat bugzilla:

Multiple denial of service flaws were found in the way StAX parser implementation of Apache CXF, an open-source web services framework, performed processing of certain XML files. If a web service application utilized the services of the StAX parser, a remote attacker could provide a specially-crafted XML file that, when processed by the application would lead to excessive system resources (CPU cycles, memory) consumption by that application.

Alerts:
Fedora FEDORA-2013-14159 2013-08-10
Fedora FEDORA-2013-14106 2013-08-10
Fedora FEDORA-2013-14159 2013-08-10
Fedora FEDORA-2013-14106 2013-08-10
Fedora FEDORA-2013-14159 2013-08-10
Fedora FEDORA-2013-14106 2013-08-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds