CVE-2014-8875: XEE
Published Dec 19, 2014
·Updated
The XMLRPCcd function in lib/pear/XML/RPC.php in Revive Adserver before 3.0.6 allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted XML-RPC request, aka an XML Entity Expansion (XEE) attack.
Affected Software
1 affected component
revive-adserver Revive Adserver<=3.0.5
Remediation
Patch Available
Event History
Dec 19, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8875?
CVE-2014-8875 has a high severity level due to its potential to cause denial of service through resource exhaustion.
2
How do I fix CVE-2014-8875?
To fix CVE-2014-8875, upgrade to Revive Adserver version 3.0.6 or later.
3
What type of attack is associated with CVE-2014-8875?
CVE-2014-8875 is associated with an XML Entity Expansion (XEE) attack that can lead to denial of service.
4
What versions of Revive Adserver are affected by CVE-2014-8875?
Revive Adserver versions prior to 3.0.6, specifically up to version 3.0.5, are affected by CVE-2014-8875.
5
Who can exploit CVE-2014-8875?
Remote attackers can exploit CVE-2014-8875 by sending crafted XML-RPC requests to the vulnerable server.