CVE-2014-6259: Medium severity zenoss vulnerability
Zenoss Core through 5 Beta 3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka ZEN-15414, a similar issue to CVE-2003-1564.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6259?
CVE-2014-6259 has a CVSS score indicating high severity due to its potential for denial of service attacks.
How do I fix CVE-2014-6259?
To mitigate CVE-2014-6259, upgrade Zenoss Core to version 5.0.1 or later, where this vulnerability is addressed.
What versions of Zenoss are affected by CVE-2014-6259?
CVE-2014-6259 affects Zenoss Core versions up to and including 5.0.0 Beta 3, along with other specified older versions.
What kind of attack can CVE-2014-6259 be used for?
CVE-2014-6259 can be exploited to create a denial of service condition through excessive memory and CPU consumption.
Are there any workarounds for CVE-2014-6259?
While the best solution is to upgrade, you can implement limits on XML document size and depth as a temporary workaround for CVE-2014-6259.