|
|
| |
|
| |
cxf: denial of service
| Package(s): | cxf |
CVE #(s): | CVE-2013-2160
|
| Created: | August 12, 2013 |
Updated: | August 14, 2013 |
| Description: |
From the Red Hat bugzilla:
Multiple denial of service flaws were found in the way StAX parser implementation of Apache CXF, an open-source web services framework, performed processing of certain XML files. If a web service application utilized the services of the StAX parser, a remote attacker could provide a specially-crafted XML file that, when processed by the application would lead to excessive system resources (CPU cycles, memory) consumption by that application. |
| Alerts: |
|
( Log in to post comments)
|
|
|