Release date:
Updated on:
Affected Systems:
Apache Group Santuario XML Security For JAVA 1.5.x
Apache Group Santuario XML Security For JAVA 1.4.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 64437
CVE (CAN) ID: CVE-2013-4517
Apache Santuario XML Security for JAVA is a library for digital signature and encryption.
Apache Santuario XML Security for JAVA 1.4.x and 1.5.x when applying Transforms, if the file type definition (DTD) is allowed, there is a denial of service type attack in implementation, which can cause OutOfMemoryError.
<* Source: James Forshaw
Link: http://santuario.apache.org/secadv.data/cve-2013-4517.txt.asc
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://santuario.apache.org/
Http://svn.apache.org/viewvc? View = revision & revision = 1537956