CVE-2013-2154
published 2013-08-20CVE-2013-2154: Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka…
PriorityP342high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
8.03%
94.1th percentile
Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions, probably related to the DSIGReference::getURIBaseTXFM function.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | xml_security_for_c | <= 1.7.0 | — |
| apache | xml_security_for_c | <= 1.7.1 | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| debian | xml-security-c | < xml-security-c 1.6.1-6 (bookworm) | xml-security-c 1.6.1-6 (bookworm) |
| debian | xml-security-c | < xml-security-c 1.6.1-7 (bookworm) | xml-security-c 1.6.1-7 (bookworm) |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-2154: xml-security-c - Stack-based buffer overflow in the XML Signature Reference functionality (xsec/d...
vendor_debian·2013·CVSS 7.5
CVE-2013-2154 [HIGH] CVE-2013-2154: xml-security-c - Stack-based buffer overflow in the XML Signature Reference functionality (xsec/d...
Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions, probably related to the DSIGReference::getURIBaseTXFM function.
Scope: local
bookworm: resolved (fixed in 1.6.1-6)
bullseye: resolved (fixed in 1.6.1-6)
forky: resolved (fixed in 1.6.1-6)
sid: resolved (fixed in 1.6.1-6)
trixie: resolved (fixed in 1.6.1-6)
Debian
CVE-2013-2210: xml-security-c - Heap-based buffer overflow in the XML Signature Reference functionality in Apach...
vendor_debian·2013·CVSS 7.5
CVE-2013-2210 [HIGH] CVE-2013-2210: xml-security-c - Heap-based buffer overflow in the XML Signature Reference functionality in Apach...
Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions. NOTE: this is due to an incorrect fix for CVE-2013-2154.
Scope: local
bookworm: resolved (fixed in 1.6.1-7)
bullseye: resolved (fixed in 1.6.1-7)
forky: resolved (fixed in 1.6.1-7)
sid: resolved (fixed in 1.6.1-7)
trixie: resolved (fixed in 1.6.1-7)
GHSA
GHSA-73cf-v5cj-5xh7: Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference
ghsa_unreviewed·2022-05-13
CVE-2013-2154 [HIGH] CWE-119 GHSA-73cf-v5cj-5xh7: Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference
Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions, probably related to the DSIGReference::getURIBaseTXFM function.
GHSA
GHSA-3gh6-67w4-wv53: Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2013-2210 [HIGH] CWE-119 GHSA-3gh6-67w4-wv53: Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1
Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions. NOTE: this is due to an incorrect fix for CVE-2013-2154.
OSV
CVE-2013-2210: Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1
osv·2013-08-20·CVSS 7.5
CVE-2013-2210 [HIGH] CVE-2013-2210: Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1
Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions. NOTE: this is due to an incorrect fix for CVE-2013-2154.
OSV
CVE-2013-2154: Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference
osv·2013-08-20·CVSS 7.5
CVE-2013-2154 [HIGH] CVE-2013-2154: Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference
Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions, probably related to the DSIGReference::getURIBaseTXFM function.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2210 xml-security-c: Heap-buffer overflow during XPointer evaluation
bugzilla·2013-06-27·CVSS 7.5
CVE-2013-2210 [HIGH] CVE-2013-2210 xml-security-c: Heap-buffer overflow during XPointer evaluation
CVE-2013-2210 xml-security-c: Heap-buffer overflow during XPointer evaluation
A heap-based buffer overflow flaw was found in the way xml-security-c, a C++ implementation of the XML Digital Signature specification, used to evaluate certain XPointer expressions. The fix to address CVE-2013-2154 flaw introduced a possibility of a heap-based buffer overflow, in the processing of malformed XPointer expression in the XML Signature References processing code. A remote attacker could provide a specially-crafted XML file to an application linked against xml-security-c that, when processed would lead to that application crash or, potentially, arbitrary code execution with the privileges of the user running the application.
References:
[1] http://santuario.apache.org/secadv.data/CVE-2013-2210.txt
Bugzilla
CVE-2013-2153 CVE-2013-2154 CVE-2013-2155 CVE-2013-2156 xml-security-c various flaws [fedora-all]
bugzilla·2013-06-18·CVSS 4.3
CVE-2013-2153 [MEDIUM] CVE-2013-2153 CVE-2013-2154 CVE-2013-2155 CVE-2013-2156 xml-security-c various flaws [fedora-all]
CVE-2013-2153 CVE-2013-2154 CVE-2013-2155 CVE-2013-2156 xml-security-c various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please
Bugzilla
CVE-2013-2153 CVE-2013-2154 CVE-2013-2155 CVE-2013-2156 xml-security-c various flaws [epel-all]
bugzilla·2013-06-18·CVSS 4.3
CVE-2013-2153 [MEDIUM] CVE-2013-2153 CVE-2013-2154 CVE-2013-2155 CVE-2013-2156 xml-security-c various flaws [epel-all]
CVE-2013-2153 CVE-2013-2154 CVE-2013-2155 CVE-2013-2156 xml-security-c various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Plea
Bugzilla
CVE-2013-2154 xml-security-c: Stack-based buffer overflow when evaluating certain XPointer expressions
bugzilla·2013-06-06·CVSS 7.5
CVE-2013-2154 [HIGH] CVE-2013-2154 xml-security-c: Stack-based buffer overflow when evaluating certain XPointer expressions
CVE-2013-2154 xml-security-c: Stack-based buffer overflow when evaluating certain XPointer expressions
A stack-based buffer overflow flaw was found in the way XML Signature Reference processing code of Apache Santuario-C++ (AKA xml-security-c), a C++ language implementation of W3C security standards for XML, performed evaluation of certain XPointer expressions (a fixed size buffer was previously allocated regardless of the actual XPointer expression length). A remote attacker could provide a specially-crafted XPointer expression to the application linked against xml-security-c performing signature verification that, when processed would lead to that application crash.
Upstream advisory:
[1] http://santuario.apache.org/secadv.data/CVE-2013-2154.txt
Relevant patch:
[2] http://svn.apache.o
http://archives.neohapsis.com/archives/fulldisclosure/2013-06/0141.htmlhttp://santuario.apache.org/secadv.data/CVE-2013-2154.txthttp://svn.apache.org/viewvc/santuario/xml-security-cpp/trunk/xsec/dsig/DSIGReference.cpp?r1=1125514&r2=1493959&pathrev=1493959&diff_format=hhttp://www.debian.org/security/2013/dsa-2710https://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3%40%3Ccommits.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/r1c07a561426ec5579073046ad7f4207cdcef452bb3100abaf908e0cd%40%3Ccommits.santuario.apache.org%3Ehttps://www.tenable.com/security/tns-2018-15http://archives.neohapsis.com/archives/fulldisclosure/2013-06/0141.htmlhttp://santuario.apache.org/secadv.data/CVE-2013-2154.txthttp://svn.apache.org/viewvc/santuario/xml-security-cpp/trunk/xsec/dsig/DSIGReference.cpp?r1=1125514&r2=1493959&pathrev=1493959&diff_format=hhttp://www.debian.org/security/2013/dsa-2710https://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3%40%3Ccommits.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/r1c07a561426ec5579073046ad7f4207cdcef452bb3100abaf908e0cd%40%3Ccommits.santuario.apache.org%3Ehttps://www.tenable.com/security/tns-2018-15
2013-08-20
Published