7.5
CVSSv2

CVE-2013-2156

Published: 20/08/2013 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the Exclusive Canonicalization functionality (xsec/canon/XSECC14n20010315.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) prior to 1.7.1 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PrefixList attribute.

Vulnerable Product Search on Vulmon Subscribe to Product

apache xml security for c\\+\\+ 1.6.0

apache xml security for c\\+\\+ 1.1.0

apache xml security for c\\+\\+ 1.6.1

apache xml security for c\\+\\+ 1.2.1

apache xml security for c\\+\\+ 1.5.1

apache xml security for c\\+\\+ 1.5.0

apache xml security for c\\+\\+ 0.2.0

apache xml security for c\\+\\+ 1.3.0

apache xml security for c\\+\\+

apache xml security for c\\+\\+ 1.4.0

apache xml security for c\\+\\+ 1.3.1

apache xml security for c\\+\\+ 1.2.0

apache xml security for c\\+\\+ 0.1.0

Vendor Advisories

James Forshaw from Context Information Security discovered several vulnerabilities in xml-security-c, an implementation of the XML Digital Security specification The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-2153 The implementation of XML digital signatures in the Santuario-C++ library is vul ...