[MAVEN:GHSA-4RV7-WJ6M-6C6R] Denial of Service due to parser crash

Severity Low
Affected Packages 2
Fixed Packages 2
CVEs 1

Withdrawn

This advisory has been withdrawn because it has been found to be a duplicate. Please see the issue here for more information.

Original Despcription

Those using FasterXML/woodstox to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

This vulnerability is only relevant for users making use of the DTD parsing functionality.

ID
MAVEN:GHSA-4RV7-WJ6M-6C6R
Severity
low
URL
https://github.com/advisories/GHSA-4rv7-wj6m-6c6r
Published
2022-09-17T00:00:41
(2 years ago)
Modified
2023-01-31T05:03:00
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.fasterxml.woodstox/woodstox-core com.fasterxml.woodstox woodstox-core < 5.4.0
Fixed pkg:maven/com.fasterxml.woodstox/woodstox-core com.fasterxml.woodstox woodstox-core = 5.4.0
Affected pkg:maven/com.fasterxml.woodstox/woodstox-core com.fasterxml.woodstox woodstox-core >= 6.0.0 < 6.4.0
Fixed pkg:maven/com.fasterxml.woodstox/woodstox-core com.fasterxml.woodstox woodstox-core = 6.4.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...