PT-2014-7125 · Zenoss · Zenoss Core
Published
2014-12-15
·
Updated
2016-03-21
·
CVE-2014-6259
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Zenoss Core versions through 5 Beta 3
Description
The issue allows remote attackers to cause a denial of service due to memory and CPU consumption. This is achieved by sending a crafted XML document that contains a large number of nested entity references, which the software does not properly detect during entity expansion.
Recommendations
For Zenoss Core versions through 5 Beta 3, consider restricting the processing of XML documents to prevent excessive entity expansion until a proper fix is available. As a temporary workaround, limiting the size of XML documents or implementing rate limiting on incoming XML requests may help minimize the risk of denial of service attacks.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zenoss Core