CVE-2013-4549: Input Validation
Published Dec 23, 2013
·Updated
QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause a denial of service (memory consumption) via an XML Entity Expansion (XEE) attack.
Affected Software
4 affected components
Digia Qt<=5.1.0
Qt QT=5.0.0
Qt QT=5.0.1
Qt QT=5.0.2
Event History
Dec 23, 2013
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-4549?
CVE-2013-4549 has a medium severity level as it allows for denial of service due to excessive memory consumption.
2
What software versions are affected by CVE-2013-4549?
CVE-2013-4549 affects Qt versions prior to 5.2, specifically versions up to and including 5.1.0.
3
How do I fix CVE-2013-4549?
To mitigate CVE-2013-4549, upgrade to Qt version 5.2 or later.
4
What type of attack does CVE-2013-4549 enable?
CVE-2013-4549 enables an XML Entity Expansion (XEE) attack that can lead to denial of service.
5
Is CVE-2013-4549 related to XML processing vulnerabilities?
Yes, CVE-2013-4549 is directly related to vulnerabilities in XML processing, allowing attackers to exploit entity expansion.