CVE-2013-1864

Portable Tool Library < 2.10.10 - Denial of Service via PXML Entity Expansion

Title source: llm
STIX 2.1

Description

The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXML document containing a large number of nested entity references, aka a "billion laughs attack."

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/82885
Patch, Vendor Advisory x_refsource_confirm
http://www.ekiga.org/news/2013-02-21/ekiga-4.0.1-stable-available
Exploit, Patch x_refsource_confirm
http://sourceforge.net/p/opalvoip/code/28856
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/58520
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/52659
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2013-March/099553.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/91439
Mailing List mailing-list x_refsource_mlist
http://seclists.org/oss-sec/2013/q1/674

Scores

EPSS 0.0273
EPSS Percentile 86.2%

Details

CWE
CWE-119
Status published
Products (7)
ekiga/ekiga < 4.0.0
opalvoip/portable_tool_library 2.10.1
opalvoip/portable_tool_library 2.10.2
opalvoip/portable_tool_library 2.10.7
opalvoip/portable_tool_library 2.10.9
suse/suse_linux_enterprise_desktop 11.0 sp3
suse/suse_linux_enterprise_software_development_kit 11.0 sp3
Published May 23, 2014
Tracked Since Feb 18, 2026