cbcvebase.
CVE-2013-2155
published 2013-08-20

CVE-2013-2155: Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a…

PriorityP431medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
5.80%
92.3th percentile
Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted length values to the (1) compareBase64StringToRaw, (2) DSIGAlgorithmHandlerDefault, or (3) DSIGAlgorithmHandlerDefault::verify functions.

Affected

14 ranges
VendorProductVersion rangeFixed in
apachexml_security_for_c<= 1.7.0
apachexml_security_for_c
apachexml_security_for_c
apachexml_security_for_c
apachexml_security_for_c
apachexml_security_for_c
apachexml_security_for_c
apachexml_security_for_c
apachexml_security_for_c
apachexml_security_for_c
apachexml_security_for_c
apachexml_security_for_c
apachexml_security_for_c
debianxml-security-c< xml-security-c 1.6.1-6 (bookworm)xml-security-c 1.6.1-6 (bookworm)

CVSS provenance

nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.