Description


Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.

Related CPE's



a

fasterxml

woodstox

2

References


https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=47434

ExploitPermissions RequiredThird Party Advisory

https://github.com/x-stream/xstream/issues/304

Issue TrackingThird Party Advisory

Weaknesses



CWE-787


CWE-121

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.5 · High

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2022-09-16T10:15:09.877

2 years ago

Last modified

2023-02-09T01:36:03.637

2 years ago