Davenport before 0.9.10 allows attackers to cause a denial of service (resource consumption) via (1) a very large XML file or (2) entity expansion attacks.
Link | Tags |
---|---|
http://www.osvdb.org/9105 | patch vdb entry |
http://www.securityfocus.com/bid/11001 | patch vdb entry |
http://sourceforge.net/project/shownotes.php?release_id=262497 | patch |
http://securitytracker.com/id?1011030 | patch vdb entry |
http://secunia.com/advisories/12337 | patch vendor advisory third party advisory |
http://sourceforge.net/mailarchive/forum.php?thread_id=5385243&forum_id=33977 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17062 | vdb entry |