Vulnerability Description
The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXML document containing a large number of nested entity references, aka a "billion laughs attack."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opalvoip | Portable Tool Library | 2.10.1 |
| Ekiga | Ekiga | <= 4.0.0 |
| Suse | Suse Linux Enterprise Software Development Kit | 11.0 |
| Suse | Suse Linux Enterprise Desktop | 11.0 |
Related Weaknesses (CWE)
References
- http://lists.fedoraproject.org/pipermail/package-announce/2013-March/099553.html
- http://osvdb.org/91439
- http://seclists.org/oss-sec/2013/q1/674
- http://secunia.com/advisories/52659
- http://sourceforge.net/p/opalvoip/code/28856ExploitPatch
- http://www.ekiga.org/news/2013-02-21/ekiga-4.0.1-stable-availablePatchVendor Advisory
- http://www.securityfocus.com/bid/58520
- https://exchange.xforce.ibmcloud.com/vulnerabilities/82885
- https://www.suse.com/support/update/announcement/2014/suse-su-20140237-1.html
- http://lists.fedoraproject.org/pipermail/package-announce/2013-March/099553.html
- http://osvdb.org/91439
- http://seclists.org/oss-sec/2013/q1/674
- http://secunia.com/advisories/52659
- http://sourceforge.net/p/opalvoip/code/28856ExploitPatch
- http://www.ekiga.org/news/2013-02-21/ekiga-4.0.1-stable-availablePatchVendor Advisory
FAQ
What is CVE-2013-1864?
CVE-2013-1864 is a vulnerability with a CVSS score of 4.3 (MEDIUM). The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of serv...
How severe is CVE-2013-1864?
CVE-2013-1864 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-1864?
Check the references section above for vendor advisories and patch information. Affected products include: Opalvoip Portable Tool Library, Ekiga Ekiga, Suse Suse Linux Enterprise Software Development Kit, Suse Suse Linux Enterprise Desktop.