[MAVEN:GHSA-5HC5-C3M9-8VCJ] Denial of Service via stack overflow

Severity Low
Affected Packages 2
Fixed Packages 2
CVEs 1

Withdrawn

This advisory has been withdrawn because it has been found to be a duplicate. Please see the issue here for more information.

Original Despcription

Those using FasterXML/woodstox to serialise XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack.

This vulnerability is only relevant for users making use of the DTD parsing functionality.

ID
MAVEN:GHSA-5HC5-C3M9-8VCJ
Severity
low
URL
https://github.com/advisories/GHSA-5hc5-c3m9-8vcj
Published
2022-09-17T00:00:41
(2 years ago)
Modified
2023-01-31T05:03:00
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.fasterxml.woodstox/woodstox-core com.fasterxml.woodstox woodstox-core < 5.4.0
Fixed pkg:maven/com.fasterxml.woodstox/woodstox-core com.fasterxml.woodstox woodstox-core = 5.4.0
Affected pkg:maven/com.fasterxml.woodstox/woodstox-core com.fasterxml.woodstox woodstox-core >= 6.0.0 < 6.4.0
Fixed pkg:maven/com.fasterxml.woodstox/woodstox-core com.fasterxml.woodstox woodstox-core = 6.4.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...