Apache disclosed CVE-2013-4517, a denial-of-service vulnerability affecting all released versions of Apache Santuario XML Security for Java. During XML Signature transform processing, the library could process Document Type Definitions (DTDs) even when secure validation was enabled, allowing a remote attacker to trigger an OutOfMemoryError and exhaust application memory. Apache fixed the issue in version 1.5.6 by disabling DTD processing in secure-validation mode and urged users of the 1.4.x and 1.5.x branches to upgrade.
Red Hat issued Moderate-severity updates for JBoss SOA Platform 5.3.1, JBoss Enterprise Web Platform 5.2.0, and JBoss Enterprise Application Platform 5.2.0, supplying updated xml-security packages for affected Red Hat Enterprise Linux deployments. Organizations running these JBoss products should install the applicable errata and restart the JBoss server process to load the remediation.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2014:1728 for JBoss Enterprise Web Platform 5.2.0 on RHEL 5 and 6. The advisory provided updated xml-security packages for CVE-2013-4517 and instructed administrators to restart the JBoss server process after updating.
Red Hat issued Moderate-severity advisory RHSA-2014:1726 for JBoss Enterprise Application Platform 5.2.0 deployments on RHEL 4, 5, and 6. It supplied updated xml-security packages to address the CVE-2013-4517 denial-of-service issue and required a JBoss server restart after installation.
Red Hat issued RHSA-2014:0582, a Moderate-severity advisory, releasing cumulative Rollup Patch 1 for JBoss SOA Platform 5.3.1. The update remediated CVE-2013-4517, which could allow remote memory-exhaustion denial of service through DTD processing in XML transforms.
Apache Santuario XML Security for Java corrected CVE-2013-4517 in version 1.5.6 by preventing DTD processing during XML Signature transforms when secure validation is enabled. The flaw, reported by James Forshaw, affected all released versions and could let an attacker trigger an OutOfMemoryError denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
rhn.redhat.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcegithub.com
Open sourcecoheigea.blogspot.com.au
Open sourcecwiki.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.