CVE-2013-1864

EUVD-2013-1867
The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXML document containing a large number of nested entity references, aka a "billion laughs attack."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
opalvoipportable_tool_library
2.10.1
opalvoipportable_tool_library
2.10.2
opalvoipportable_tool_library
2.10.7
opalvoipportable_tool_library
2.10.9
ekigaekiga
𝑥
≤ 4.0.0
susesuse_linux_enterprise_software_development_kit
11.0:sp3
susesuse_linux_enterprise_desktop
11.0:sp3
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ptlib
hardy
dne
lucid
ignored
oneiric
ignored
precise
ignored
quantal
ignored
raring
not-affected
saucy
not-affected
trusty
dne
utopic
not-affected
vivid
not-affected
wily
not-affected
xenial
not-affected
yakkety
not-affected
zesty
not-affected
pwlib
hardy
ignored
lucid
ignored
oneiric
ignored
precise
ignored
quantal
dne
raring
dne
saucy
dne
trusty
dne
utopic
dne
vivid
dne
wily
dne
xenial
dne
yakkety
dne
zesty
dne