PT-2017-8514 · Mini-Xml+2 · Mxml+2

Andrej Nemec

·

Publicado

2014-06-05

·

Atualizado

2021-06-17

·

CVE-2016-4571

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions mxml versions 2.7 through 2.9
Description The issue allows remote attackers to cause a denial of service, specifically stack consumption, by utilizing a crafted XML file. This is related to the mxml write node function in mxml-file.c.
Recommendations For mxml versions 2.7 through 2.9, consider updating to a version where this issue is fixed, if available. As a temporary workaround, restrict the processing of external XML files to minimize the risk of exploitation.

Correção

DoS

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1729
CVE-2016-4571
DLA-1641-1
MGASA-2017-0103
OPENSUSE-SU-2024:10530-1
SUSE-SU-2017:3060-1

Produtos afetados

Alt Linux
Suse
Mxml