exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Apache Santuario XML Security For C++ Heap Overflow

Apache Santuario XML Security For C++ Heap Overflow
Posted Jun 27, 2013
Authored by Jon Erickson

The attempted fix to address CVE-2013-2154 introduced the possibility of a heap overflow, possibly leading to arbitrary code execution, in the processing of malformed XPointer expressions in the XML Signature Reference processing code. An attacker could use this to exploit an application performing signature verification if the application does not block the evaluation of such references prior to performing the verification step. The exploit would occur prior to the actual verification of the signature, so does not require authenticated content. Apache Santuario XML Security for C++ library versions prior to 1.7.2 are affected.

tags | advisory, overflow, arbitrary, code execution
advisories | CVE-2013-2154, CVE-2013-2210
SHA-256 | ed557eaf432b8220b8a580b3a0a313162a1d2211f6e1ea637a19dc2d29e16038

Apache Santuario XML Security For C++ Heap Overflow

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

CVE-2013-2210: Apache Santuario XML Security for C++ contains a heap
overflow during XPointer evaluation

Severity: Critical

Vendor: The Apache Software Foundation

Versions Affected: Apache Santuario XML Security for C++ library versions
prior to V1.7.2

Description: The attempted fix to address CVE-2013-2154 introduced the
possibility of a heap overflow, possibly leading to arbitrary code
execution, in the processing of malformed XPointer expressions in the
XML Signature Reference processing code.

An attacker could use this to exploit an application performing
signature verification if the application does not block the
evaluation of such references prior to performing the verification
step. The exploit would occur prior to the actual verification of
the signature, so does not require authenticated content.

Mitigation: Applications that do not otherwise prevent the evaluation of
XPointer expressions during signature verification and are using library
versions older than V1.7.2 should upgrade as soon as possible. Distributors
of older versions should apply the patches from this subversion revision:

http://svn.apache.org/viewvc?view=revision&revision=r1496703

Credit: This issue was reported by Jon Erickson of iSIGHT Partners Labs

References:
http://santuario.apache.org/
http://santuario.apache.org/secadv.data/CVE-2013-2154.txt
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.13 (Darwin)

iQIcBAEBCgAGBQJRy4zwAAoJEDeLhFQCJ3lin88QALve0Q1GXUQMQsJeqpS2IKI0
FUHhlVhOBVUOjhT3Q1+TfXHqTubJ6Rb6sAhPHB1YzKkeJwyWcRVKi4/1AVGcp3Nq
e1fBNz3zrLQpYyjkmoPxUv/SADRtn8mbED1/WAJ2K3iQJ951FWkDpC8MTJhlJBEJ
FUh6hXMZJpiA4KGidsAJDpvsqZhOAUKDwxD7s0rdmadc+/dB2PigDXcJxgdG9Dz3
eQYS+UkvhUCAIU8TxJaCqEECGYAe015AikbroMHUdhmNsP4otke2HOBz1xcs8YCb
KyNlm0HmQ7S4Qv0UEeAyCzHXITAw7lRD5tp7/y9ZcHbLPZHAgMtFmcup5O7/xrVb
h9Mh+uZ1C2atEPd/ME3/JqNDSAzxcT+Wa3SEQrnQXUVfpomE3Pztg3EUYPL8x/ln
WO+pobIyTMPTEQ1rTI3LPliG8JDU4QS1HY+VQzlspNsVF2buDrOprgKAYx3MWnz3
/YvThnNNumXx7EjX/KN5RVmLavWSfJSGk725dYcaePAtLNIBHIWbkvZitsJSlrg7
0mTj8eAza79/UYWaWyz0zzd1y5bYq0m582hwSI9r45hdB32agvi5IqkAxhswBHTk
B2xga2QZynAmJGHBmvPXq8fmwFw7VOZ6H+M55fNCHnb4XA96OZGb5+aZCRX2m5+X
Gf+o5DTdMpinSzoT2ax2
=hZu/
-----END PGP SIGNATURE-----

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close