CVE-2014-0110: Medium severity Apache CXF vulnerability
Apache CXF before 2.6.14 and 2.7.x before 2.7.11 allows remote attackers to cause a denial of service (/tmp disk consumption) via a large invalid SOAP message.
Other sources
If a SOAP message generates a fault on parsing or processing, but is not fully consumed, it is possible to cause the server to read all of the remaining data and to save it to a temp file. By dynamically creating data, you can cause the entire /tmp directory to fill.
Affected versions: Apach CXF 2.6.x < 2.6.14 Apach CXF 2.7.x < 2.7.11
References: http://cxf.apache.org/security-advisories.data/CVE-2014-0110.txt.asc
Upstream fix: https://git-wip-us.apache.org/repos/asf?p=cxf.git;a=commit;h=8f4799b5bc5ed0fe62d6e018c45d960e3652373e
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0110?
CVE-2014-0110 is classified as a denial of service vulnerability due to excessive disk consumption.
How do I fix CVE-2014-0110?
To fix CVE-2014-0110, upgrade Apache CXF to version 2.6.14 or later for the 2.6.x branch, or version 2.7.11 or later for the 2.7.x branch.
Which versions of Apache CXF are affected by CVE-2014-0110?
CVE-2014-0110 affects Apache CXF versions prior to 2.6.14 and 2.7.11.
What type of attack does CVE-2014-0110 enable?
CVE-2014-0110 allows attackers to cause a denial of service by sending large invalid SOAP messages that lead to excessive disk usage.
Is CVE-2014-0110 associated with any specific software packages?
CVE-2014-0110 is associated with Apache CXF packages, particularly versions 2.4.0 to 2.6.13 and 2.7.0 to 2.7.10.