Vulnerability Description
XML external entity (XXE) vulnerability in PyAMF before 0.8.0 allows remote attackers to cause a denial of service or read arbitrary files via a crafted Action Message Format (AMF) payload.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pyamf | Pyamf | < 0.8.0 |
Related Weaknesses (CWE)
References
- http://www.ocert.org/advisories/ocert-2015-011.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/archive/1/537151/100/0/threadedBroken Link
- https://github.com/hydralabs/pyamf/pull/58PatchThird Party Advisory
- https://github.com/hydralabs/pyamf/releases/tag/v0.8.0Release Notes
- http://www.ocert.org/advisories/ocert-2015-011.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/archive/1/537151/100/0/threadedBroken Link
- https://github.com/hydralabs/pyamf/pull/58PatchThird Party Advisory
- https://github.com/hydralabs/pyamf/releases/tag/v0.8.0Release Notes
FAQ
What is CVE-2015-8549?
CVE-2015-8549 is a vulnerability with a CVSS score of 7.1 (HIGH). XML external entity (XXE) vulnerability in PyAMF before 0.8.0 allows remote attackers to cause a denial of service or read arbitrary files via a crafted Action Message Format (AMF) payload.
How severe is CVE-2015-8549?
CVE-2015-8549 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-8549?
Check the references section above for vendor advisories and patch information. Affected products include: Pyamf Pyamf.