// For flags

CVE-2013-2210

Apache Santuario XML Security for C++ Heap Overflow

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions. NOTE: this is due to an incorrect fix for CVE-2013-2154.

Desbordamiento de búfer basado en memoria dinámica en la funcionalidad XML Signature Reference ein Apache Santuario XML Security para C++ (aka xml-security-c) anterior a 1.7.2, permite a atacantes dependientes del contexto provocar una denegación de servicio (caída) y posiblemente ejecutar código arbitrario a través de expresiones Xpointer mal formadas. NOTA: Esto se debe a una corrección incorrecta del CVE-2013-2154.

The attempted fix to address CVE-2013-2154 introduced the possibility of a heap overflow, possibly leading to arbitrary code execution, in the processing of malformed XPointer expressions in the XML Signature Reference processing code. An attacker could use this to exploit an application performing signature verification if the application does not block the evaluation of such references prior to performing the verification step. The exploit would occur prior to the actual verification of the signature, so does not require authenticated content. Apache Santuario XML Security for C++ library versions prior to 1.7.2 are affected.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2013-02-19 CVE Reserved
  • 2013-06-27 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apache
Search vendor "Apache"
Xml Security For C\+\+
Search vendor "Apache" for product "Xml Security For C\+\+"
<= 1.7.1
Search vendor "Apache" for product "Xml Security For C\+\+" and version " <= 1.7.1"
-
Affected
Apache
Search vendor "Apache"
Xml Security For C\+\+
Search vendor "Apache" for product "Xml Security For C\+\+"
0.1.0
Search vendor "Apache" for product "Xml Security For C\+\+" and version "0.1.0"
-
Affected
Apache
Search vendor "Apache"
Xml Security For C\+\+
Search vendor "Apache" for product "Xml Security For C\+\+"
0.2.0
Search vendor "Apache" for product "Xml Security For C\+\+" and version "0.2.0"
-
Affected
Apache
Search vendor "Apache"
Xml Security For C\+\+
Search vendor "Apache" for product "Xml Security For C\+\+"
1.1.0
Search vendor "Apache" for product "Xml Security For C\+\+" and version "1.1.0"
-
Affected
Apache
Search vendor "Apache"
Xml Security For C\+\+
Search vendor "Apache" for product "Xml Security For C\+\+"
1.2.0
Search vendor "Apache" for product "Xml Security For C\+\+" and version "1.2.0"
-
Affected
Apache
Search vendor "Apache"
Xml Security For C\+\+
Search vendor "Apache" for product "Xml Security For C\+\+"
1.2.1
Search vendor "Apache" for product "Xml Security For C\+\+" and version "1.2.1"
-
Affected
Apache
Search vendor "Apache"
Xml Security For C\+\+
Search vendor "Apache" for product "Xml Security For C\+\+"
1.3.0
Search vendor "Apache" for product "Xml Security For C\+\+" and version "1.3.0"
-
Affected
Apache
Search vendor "Apache"
Xml Security For C\+\+
Search vendor "Apache" for product "Xml Security For C\+\+"
1.3.1
Search vendor "Apache" for product "Xml Security For C\+\+" and version "1.3.1"
-
Affected
Apache
Search vendor "Apache"
Xml Security For C\+\+
Search vendor "Apache" for product "Xml Security For C\+\+"
1.4.0
Search vendor "Apache" for product "Xml Security For C\+\+" and version "1.4.0"
-
Affected
Apache
Search vendor "Apache"
Xml Security For C\+\+
Search vendor "Apache" for product "Xml Security For C\+\+"
1.5.0
Search vendor "Apache" for product "Xml Security For C\+\+" and version "1.5.0"
-
Affected
Apache
Search vendor "Apache"
Xml Security For C\+\+
Search vendor "Apache" for product "Xml Security For C\+\+"
1.5.1
Search vendor "Apache" for product "Xml Security For C\+\+" and version "1.5.1"
-
Affected
Apache
Search vendor "Apache"
Xml Security For C\+\+
Search vendor "Apache" for product "Xml Security For C\+\+"
1.6.0
Search vendor "Apache" for product "Xml Security For C\+\+" and version "1.6.0"
-
Affected
Apache
Search vendor "Apache"
Xml Security For C\+\+
Search vendor "Apache" for product "Xml Security For C\+\+"
1.6.1
Search vendor "Apache" for product "Xml Security For C\+\+" and version "1.6.1"
-
Affected
Apache
Search vendor "Apache"
Xml Security For C\+\+
Search vendor "Apache" for product "Xml Security For C\+\+"
1.7.0
Search vendor "Apache" for product "Xml Security For C\+\+" and version "1.7.0"
-
Affected