PT-2013-5825 · Ibm+6 · Ibm Aix+9

Published

2013-10-16

·

Updated

2024-06-15

·

CVE-2013-5823

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Oracle Java SE versions 7u40 and earlier Oracle Java SE versions 6u60 and earlier JRockit versions R28.2.8 and earlier JRockit versions R27.7.6 and earlier Java SE Embedded versions 7u40 and earlier xmlsec (affected versions not specified) IBM AIX (affected versions not specified)
Description The issue allows remote attackers to affect availability via unknown vectors related to Security. It also concerns a denial of service vulnerability, where checking the signature of a large message can cause an endless loop in the expandSize(int newPos) method of the org.apache.xml.security.utils.UnsyncByteArrayOutputStream class. A remote attacker could exploit this flaw by supplying crafted XML to lead to a denial of service.
Recommendations For Oracle Java SE versions 7u40 and earlier, update to a version later than 7u40. For Oracle Java SE versions 6u60 and earlier, update to a version later than 6u60. For JRockit versions R28.2.8 and earlier, update to a version later than R28.2.8. For JRockit versions R27.7.6 and earlier, update to a version later than R27.7.6. For Java SE Embedded versions 7u40 and earlier, update to a version later than 7u40. For xmlsec, avoid checking signatures of messages larger than 512 MB until a patch is available. For IBM AIX, at the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CESA-2013_1451
CESA-2013_1505
CVE-2013-5823
GHSA-8GWC-X7MG-7P7P
HPSBUX02943
HPSBUX02944
MGASA-2013-0322
MGASA-2013-0323
OPENSUSE-SU-2024:10534-1
RHSA-2013:1440
RHSA-2013:1447
RHSA-2013:1451
RHSA-2013:1505
RHSA-2013:1507
RHSA-2013:1508
RHSA-2013:1793
RHSA-2013_1440
RHSA-2013_1447
RHSA-2013_1451
RHSA-2013_1505
RHSA-2013_1507
RHSA-2013_1508
RHSA-2014:0414
RHSA-2014_0414

Affected Products

Centos
Hp-Ux
Ibm Aix
Jrockit
Java Platform
Java Se Embedded
Oracle Java Se
Red Hat
Suse
Xmlsec