CVE-2013-2155: Input Validation
Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted length values to the (1) compareBase64StringToRaw, (2) DSIGAlgorithmHandlerDefault, or (3) DSIGAlgorithmHandlerDefault::verify functions.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2155?
CVE-2013-2155 has a severity rating of medium and can lead to denial of service and signature spoofing.
How do I fix CVE-2013-2155?
To fix CVE-2013-2155, upgrade Apache Santuario XML Security for C++ to version 1.7.1 or later.
What versions are affected by CVE-2013-2155?
CVE-2013-2155 affects Apache Santuario XML Security for C++ versions prior to 1.7.1.
What types of attacks can CVE-2013-2155 enable?
CVE-2013-2155 can enable remote attackers to perform denial of service and potentially spoof signatures.
Is there any workaround for CVE-2013-2155?
There are no known workarounds for CVE-2013-2155; upgrading is the recommended action.