Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2014.0001
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2014-0001)
Summary:The remote host is missing an update for the 'cxf, jacorb, wss4j' package(s) announced via the MGASA-2014-0001 advisory.
Description:Summary:
The remote host is missing an update for the 'cxf, jacorb, wss4j' package(s) announced via the MGASA-2014-0001 advisory.

Vulnerability Insight:
Multiple denial of service flaws were found in the way StAX parser
implementation of Apache CXF, an open-source web services framework,
performed processing of certain XML files. If a web service application
utilized the services of the StAX parser, a remote attacker could provide
a specially-crafted XML file that, when processed by the application would
lead to excessive system resources (CPU cycles, memory) consumption by
that application (CVE-2013-2160).

Affected Software/OS:
'cxf, jacorb, wss4j' package(s) on Mageia 3.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-2160
http://jira.codehaus.org/browse/WSTX-285
http://jira.codehaus.org/browse/WSTX-287
https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c@%3Ccommits.cxf.apache.org%3E
https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf@%3Ccommits.cxf.apache.org%3E
https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E
https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6@%3Ccommits.cxf.apache.org%3E
https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4@%3Ccommits.cxf.apache.org%3E
https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e@%3Ccommits.cxf.apache.org%3E
RedHat Security Advisories: RHSA-2013:1028
http://rhn.redhat.com/errata/RHSA-2013-1028.html
RedHat Security Advisories: RHSA-2013:1437
http://rhn.redhat.com/errata/RHSA-2013-1437.html
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.