CVE-2013-4199: Input Validation
(1) cbdecode.py and (2) linkintegrity.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users to cause a denial of service (resource consumption) via a large zip archive, which is expanded (decompressed).
Other sources
A denial of service flaw was found in the way Plone, a user friendly and powerful content management system, used to previously expand certain zip archives. Remote attacker, authenticated Plone user could issue Zip archive expand request with specially-crafted archive that, when processed would lead to uncontrolled resources consumption (denial of service).
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4199?
CVE-2013-4199 has been classified as a denial of service vulnerability due to resource consumption.
How do I fix CVE-2013-4199?
To fix CVE-2013-4199, users should upgrade Plone to a version that is not affected, specifically versions beyond 4.3.1.
What software is affected by CVE-2013-4199?
CVE-2013-4199 affects Plone versions 2.1 through 4.3.1.
Can unprivileged users exploit CVE-2013-4199?
Yes, remote authenticated users can exploit CVE-2013-4199 by sending a large zip archive to the server.
What impact does CVE-2013-4199 have on systems?
CVE-2013-4199 can lead to a denial of service condition, potentially causing system outages due to resource exhaustion.