First published: Fri Dec 19 2014(Updated: )
The XML_RPC_cd function in lib/pear/XML/RPC.php in Revive Adserver before 3.0.6 allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted XML-RPC request, aka an XML Entity Expansion (XEE) attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Revive Adserver | <=3.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8875 has a high severity level due to its potential to cause denial of service through resource exhaustion.
To fix CVE-2014-8875, upgrade to Revive Adserver version 3.0.6 or later.
CVE-2014-8875 is associated with an XML Entity Expansion (XEE) attack that can lead to denial of service.
Revive Adserver versions prior to 3.0.6, specifically up to version 3.0.5, are affected by CVE-2014-8875.
Remote attackers can exploit CVE-2014-8875 by sending crafted XML-RPC requests to the vulnerable server.