CVE-2013-2154: Buffer Overflow
Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions, probably related to the DSIGReference::getURIBaseTXFM function.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2154?
CVE-2013-2154 has a severity rating that can lead to a denial of service and potential arbitrary code execution.
How do I fix CVE-2013-2154?
To fix CVE-2013-2154, update Apache XML Security for C++ to version 1.7.1 or later.
What causes CVE-2013-2154?
CVE-2013-2154 is caused by a stack-based buffer overflow in the XML Signature Reference functionality.
Which versions of Apache XML Security for C++ are affected by CVE-2013-2154?
Apache XML Security for C++ versions up to 1.7.0 and certain specific earlier versions are affected by CVE-2013-2154.
Can CVE-2013-2154 lead to remote code execution?
Yes, CVE-2013-2154 can potentially allow context-dependent attackers to execute arbitrary code.