Vulnerability Name:

CVE-2013-1864 (CCN-82885)

Assigned:2013-01-09
Published:2013-01-09
Updated:2017-08-29
Summary:The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXML document containing a large number of nested entity references, aka a "billion laughs attack."
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2013-1864

Source: CCN
Type: Ptlib Web page
Ptlib

Source: FEDORA
Type: UNKNOWN
FEDORA-2013-2998

Source: OSVDB
Type: UNKNOWN
91439

Source: MLIST
Type: UNKNOWN
[oss-security] 20130315 Re: CVE request: billion laughs flaw in ptlib

Source: CCN
Type: SA52659
Ptlib Entity Expansion Denial of Service Vulnerability

Source: SECUNIA
Type: UNKNOWN
52659

Source: CONFIRM
Type: Exploit, Patch
http://sourceforge.net/p/opalvoip/code/28856

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.ekiga.org/news/2013-02-21/ekiga-4.0.1-stable-available

Source: BID
Type: UNKNOWN
58520

Source: CCN
Type: BID-58520
PTLib CVE-2013-1864 XML Parsing Denial of Service Vulnerability

Source: CCN
Type: Red Hat Bugzilla Bug 922177
ptlib: denial of service processing certain XML documents

Source: XF
Type: UNKNOWN
ptlib-xml-dos(82885)

Source: XF
Type: UNKNOWN
ptlib-xml-dos(82885)

Source: SUSE
Type: UNKNOWN
SUSE-SU-2014:0237

Vulnerable Configuration:Configuration 1:
  • cpe:/a:opalvoip:portable_tool_library:2.10.1:*:*:*:*:*:*:*
  • OR cpe:/a:opalvoip:portable_tool_library:2.10.2:*:*:*:*:*:*:*
  • OR cpe:/a:opalvoip:portable_tool_library:2.10.7:*:*:*:*:*:*:*
  • OR cpe:/a:opalvoip:portable_tool_library:2.10.9:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:ekiga:ekiga:*:*:*:*:*:*:*:* (Version <= 4.0.0)

  • Configuration 3:
  • cpe:/a:suse:suse_linux_enterprise_software_development_kit:11.0:sp3:*:*:*:*:*:*
  • OR cpe:/o:suse:suse_linux_enterprise_desktop:11.0:sp3:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:55285
    P
    Security update for log4j (Important)
    2021-12-17
    oval:org.opensuse.security:def:26168
    P
    Security update for the Linux Kernel (Important)
    2021-11-19
    oval:org.opensuse.security:def:55936
    P
    Security update for fetchmail (Moderate)
    2021-08-18
    oval:org.opensuse.security:def:26104
    P
    Security update for libcares2 (Important)
    2021-08-16
    oval:org.opensuse.security:def:20131864
    V
    CVE-2013-1864
    2021-08-15
    oval:org.opensuse.security:def:56048
    P
    Security update for qemu (Moderate)
    2021-07-21
    oval:org.opensuse.security:def:57479
    P
    Security update for systemd (Important)
    2021-07-21
    oval:org.opensuse.security:def:26093
    P
    Security update for dbus-1 (Important)
    2021-07-21
    oval:org.opensuse.security:def:26092
    P
    Security update for the Linux Kernel (Important)
    2021-07-20
    oval:org.opensuse.security:def:36543
    P
    pwlib-1.10.10-120.35.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:55179
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:56010
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:54768
    P
    Security update for python-cryptography (Important)
    2021-03-02
    oval:org.opensuse.security:def:55844
    P
    Security update for the Linux Kernel (Important)
    2021-02-11
    oval:org.opensuse.security:def:26771
    P
    libvirt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26412
    P
    Security update for tor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26989
    P
    man on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27709
    P
    Security update for bash
    2020-12-01
    oval:org.opensuse.security:def:28781
    P
    Security update for libxslt
    2020-12-01
    oval:org.opensuse.security:def:55006
    P
    rsyslog on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26810
    P
    pure-ftpd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26413
    P
    Security update for go1.8 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27042
    P
    taglib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27793
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28816
    P
    Security update for pwlib
    2020-12-01
    oval:org.opensuse.security:def:56129
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:26296
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26824
    P
    sudo on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26424
    P
    Security update for enigmail (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27091
    P
    bind on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27366
    P
    a2ps-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27944
    P
    Security update for GraphicsMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:57405
    P
    Security update for libgadu
    2020-12-01
    oval:org.opensuse.security:def:26377
    P
    Security update for kauth, kdelibs4 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26868
    P
    avahi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26488
    P
    Security update for cacti, cacti-spine (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27130
    P
    g3utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27367
    P
    ant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27997
    P
    Security update for MozillaFirefox, mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:55451
    P
    Security update for MozillaFirefox and mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:26434
    P
    Security update for pdns (Important)
    2020-12-01
    oval:org.opensuse.security:def:27506
    P
    libxml on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26616
    P
    mutt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27144
    P
    gvim on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27378
    P
    build on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28046
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54605
    P
    libspice-client-glib-2_0-8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55736
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:26518
    P
    OpenEXR on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27541
    P
    pwlib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26697
    P
    findutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27188
    P
    libgnomesu on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27442
    P
    libevent-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28085
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54606
    P
    libspice-server1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26669
    P
    apache2-mod_perl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26754
    P
    libneon27 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27826
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27570
    P
    t1lib-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28099
    P
    Security update for git (Important)
    2020-12-01
    oval:org.opensuse.security:def:54628
    P
    libzip2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26722
    P
    kbd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26838
    P
    w3m on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27861
    P
    Security update for pwlib
    2020-12-01
    oval:org.opensuse.security:def:27652
    P
    Security update for mozilla-nspr, mozilla-nss
    2020-12-01
    oval:org.opensuse.security:def:28143
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.mitre.oval:def:25328
    P
    SUSE-SU-2014:0237-1 -- Security update for pwlib
    2014-09-08
    oval:com.ubuntu.precise:def:20131864000
    V
    CVE-2013-1864 on Ubuntu 12.04 LTS (precise) - medium.
    2014-05-23
    oval:com.ubuntu.trusty:def:20131864000
    V
    CVE-2013-1864 on Ubuntu 14.04 LTS (trusty) - medium.
    2014-05-23
    oval:com.ubuntu.xenial:def:201318640000000
    V
    CVE-2013-1864 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-05-23
    oval:com.ubuntu.xenial:def:20131864000
    V
    CVE-2013-1864 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-05-23
    oval:org.opensuse.security:def:80113
    P
    Security update for pwlib
    2014-01-27
    BACK
    opalvoip portable tool library 2.10.1
    opalvoip portable tool library 2.10.2
    opalvoip portable tool library 2.10.7
    opalvoip portable tool library 2.10.9
    ekiga ekiga *
    suse suse linux enterprise software development kit 11.0 sp3
    suse suse linux enterprise desktop 11.0 sp3