PT-2017-8513 · Mxml+2 · Mxml+2
Andrej Nemec
·
Publicado
2014-06-05
·
Atualizado
2021-06-16
·
CVE-2016-4570
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
mxml versions 2.7 through 2.9
Description
The issue allows remote attackers to cause a denial of service, specifically stack consumption, by using a crafted XML file. This is related to the mxmlDelete function in mxml-node.c.
Recommendations
For versions 2.7 through 2.9, consider avoiding the use of the mxmlDelete function until a patch is available. As a temporary workaround, restrict the processing of external XML files to minimize the risk of exploitation.
Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Mxml