The XML parser in IBM Rational DOORS Next Generation 4.x before 4.0.7 iFix3 and 5.x before 5.0.2 and Rational Requirements Composer 2.x and 3.x before 3.0.1.6 iFix5 and 4.x before 4.0.7 iFix3 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
References
Link Resource
http://www-01.ibm.com/support/docview.wss?uid=swg21698248 Patch Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: ibm

Published: 2015-03-18T10:00:00

Updated: 2015-03-18T01:57:01

Reserved: 2014-11-18T00:00:00


Link: CVE-2015-0132

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2015-03-18T10:59:05.247

Modified: 2015-03-18T16:13:19.190


Link: CVE-2015-0132

JSON object: View

cve-icon Redhat Information

No data.

CWE