PT-2016-4082 · Soap::Lite+1 · Soap Lite+1
Publicado
2016-11-22
·
Atualizado
2017-08-09
·
CVE-2015-8978
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Soap Lite versions 1.14 and earlier
Description
The issue allows an example attack where an attacker defines multiple XML entities, each consisting of multiple instances of the previous entity. This can lead to excessive computer memory usage when handling an external SOAP call, potentially exceeding the available memory for the process parsing the XML.
Recommendations
For Soap Lite versions 1.14 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Soap Lite
Suse