Restlet Framework XML Entity Expansion Denial of Service Vulnerability
BID:65574
Info
Restlet Framework XML Entity Expansion Denial of Service Vulnerability
| Bugtraq ID: | 65574 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-1868 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 09 2014 12:00AM |
| Updated: | Feb 09 2014 12:00AM |
| Credit: | Alvaro Munoz, HP Fortify. |
| Vulnerable: |
Restlet Restlet Framework 2.1.6 |
| Not Vulnerable: |
Restlet Restlet Framework 2.1.7 |
Discussion
Restlet Framework XML Entity Expansion Denial of Service Vulnerability
Restlet Framework is prone to a denial-of-service vulnerability.
Successful exploits may allow an attacker to cause an affected application to consume excessive amounts of memory, resulting in a denial-of-service condition.
Versions prior to Restlet Framework 2.1.7 are vulnerable.
Restlet Framework is prone to a denial-of-service vulnerability.
Successful exploits may allow an attacker to cause an affected application to consume excessive amounts of memory, resulting in a denial-of-service condition.
Versions prior to Restlet Framework 2.1.7 are vulnerable.
Exploit / POC
Restlet Framework XML Entity Expansion Denial of Service Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].