exiv2: denial of service
| Package(s): | exiv2 | CVE #(s): | |||||||||||||
| Created: | March 4, 2016 | Updated: | March 9, 2016 | ||||||||||||
| Description: | From the Red Hat bug report: Exempi contains code to protect against a denial-service-attack related to XML entity expansion ("billion laughs attack"), but it is not compiled into the Fedora package because BanAllEntityUsage is not defined when the package is compiled. | ||||||||||||||
| Alerts: |
| ||||||||||||||
