CVE-2015-0851: Medium severity xmltooling vulnerability
Published Aug 12, 2015
·Updated
XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.
Affected Software
1 affected component
Xmltooling Project Xmltooling<=1.5.4
Event History
Aug 12, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0851?
CVE-2015-0851 is classified as having a high severity level due to its potential to cause denial of service.
2
How do I fix CVE-2015-0851?
To fix CVE-2015-0851, upgrade XMLTooling to version 1.5.5 or later.
3
Who is affected by CVE-2015-0851?
CVE-2015-0851 affects users of XMLTooling versions prior to 1.5.5, including those using OpenSAML-C and Shibboleth Service Provider.
4
What impact does CVE-2015-0851 have?
CVE-2015-0851 allows remote attackers to cause a denial of service by sending schema-invalid XML data.
5
Is CVE-2015-0851 a remote exploit?
Yes, CVE-2015-0851 is a remote exploit that leverages malformed XML input to crash the application.