The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consumption) via a large integer in a %MAKETEXT% macro.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2012-6329 | vendor advisory |
http://sourceforge.net/mailarchive/message.php?msg_id=30219695 | mailing list |
http://www.securityfocus.com/bid/56950 | vdb entry |