CVE-2013-5823
Apache XML Security For Java vulnerable to Infinite Loop
EPSS 5.8%
Description
Affected versions of xmlsec are subject to a denial of service vulnerability. Should a user check the signature of a message larger than 512 MB, the method `expandSize(int newPos)` of class `org.apache.xml.security.utils.UnsyncByteArrayOutputStream` goes in an endless loop. A remote attacker could use this flaw to supply crafted XML that would lead to a denial of service.
How to fix CVE-2013-5823
To remediate CVE-2013-5823, upgrade the affected package to a fixed version below.
- Maven/org.apache.santuario:xmlsec—upgrade to 1.4.8 or later
Is CVE-2013-5823 being exploited?
Moderate — EPSS is 5.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 1.4.0, < 1.4.8