Vulnerabilities > CVE-2013-1864 - Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL

Summary

The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXML document containing a large number of nested entity references, aka a "billion laughs attack."

Common Attack Pattern Enumeration and Classification (CAPEC)

  • Buffer Overflow via Environment Variables
    This attack pattern involves causing a buffer overflow through manipulation of environment variables. Once the attacker finds that they can modify an environment variable, they may try to overflow associated buffers. This attack leverages implicit trust often placed in environment variables.
  • Overflow Buffers
    Buffer Overflow attacks target improper or missing bounds checking on buffer operations, typically triggered by input injected by an attacker. As a consequence, an attacker is able to write past the boundaries of allocated buffer regions in memory, causing a program crash or potentially redirection of execution as per the attackers' choice.
  • Client-side Injection-induced Buffer Overflow
    This type of attack exploits a buffer overflow vulnerability in targeted client software through injection of malicious content from a custom-built hostile service.
  • Filter Failure through Buffer Overflow
    In this attack, the idea is to cause an active filter to fail by causing an oversized transaction. An attacker may try to feed overly long input strings to the program in an attempt to overwhelm the filter (by causing a buffer overflow) and hoping that the filter does not fail securely (i.e. the user input is let into the system unfiltered).
  • MIME Conversion
    An attacker exploits a weakness in the MIME conversion routine to cause a buffer overflow and gain control over the mail server machine. The MIME system is designed to allow various different information formats to be interpreted and sent via e-mail. Attack points exist when data are converted to MIME compatible format and back.

Nessus

  • NASL familyDenial of Service
    NASL idEKIGA_4_0_1.NASL
    descriptionAccording to the version in its SIP banner, the installed version of Ekiga on the remote host is earlier than 4.0.1 and thus contains a version of the ptlib library that fails to conduct proper length checks during XML expansion. A remote, unauthenticated attacker could exploit this issue to consume extreme amounts of CPU and memory through the use of a specially crafted XML document.
    last seen2020-06-01
    modified2020-06-02
    plugin id66033
    published2013-04-19
    reporterThis script is Copyright (C) 2013-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/66033
    titleEkiga < 4.0.1 ptlib XML Expansion Recursion DoS
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_PWLIB-140127.NASL
    descriptionThis update fixes a XML DoS vulnerability in pwlib. CVE-2013-1864 has been assigned to this issue.
    last seen2020-06-05
    modified2014-02-17
    plugin id72536
    published2014-02-17
    reporterThis script is Copyright (C) 2014-2020 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/72536
    titleSuSE 11.3 Security Update : pwlib (SAT Patch Number 8838)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2013-2998.NASL
    descriptionNew upstream ekiga 4.0.1 release - Core fixes - Fix crash when quitting ekiga while receiving presence information - Fix crash when quitting ekiga right after starting it (before STUN ending) - Fix crash when disabling an account while icons in roster are changing - Fix crash when receiving call a second time - Fix crash in XML parsing in case of malicious code (CVE-2012-5621) - Fix increasing CPU usage after hours of usage caused by endless OPTIONS - Several fixes for H.323 : - fix H.323 parsing - add the username in authentication - fix unregistering the gatekeeper - fix registration - assign gk_name only if success - do not propose adding an H.323 account if the protocol is not built-in - Fix registration for registrars accepting the last Contact item offered - Allow to change the REGISTER compatibility mode of an existing registration - Fix impossibility to hangup active call after a missed call - Fix busy or call forwarding on busy occuring when connection is released - Fix subscribing/unsubscribing when enabling and disabling SIP accounts - Do not show is-typing messages sent by other programs during chatting - Stop ongoing registration when remove account - Use meaningful names for ALSA sub-devices - Allow to enter contact addresses without host part, and choose the host later - Increase number of characters shown in device names - Use a better icon for call history in addressbook - Show the address instead of
    last seen2020-03-17
    modified2013-03-04
    plugin id64984
    published2013-03-04
    reporterThis script is Copyright (C) 2013-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/64984
    titleFedora 18 : ekiga-4.0.1-1.fc18 / opal-3.10.10-1.fc18 / ptlib-2.10.10-1.fc18 (2013-2998)