Davenport long XML file denial of service

davenport-long-xml-dos (17062) The risk level is classified as LowLow Risk

Description:

Davenport is vulnerable to a denial of service attack. By sending long XML file, a remote authenticated attacker could consume large amounts of system resources.

Platforms Affected:

  • eglass1, Davenport prior to 0.9.10

Remedy:

Upgrade to the latest version of Davenport (0.9.10 or later), available from the Davenport Web page. See References.

Consequences:

Denial of Service

References:

  • Davenport Web page, Project: Davenport WebDAV-CIFS (SMB) Gateway: Summary at http://sourceforge.net/projects/davenport/.
  • BID-11001: Davenport XML Expansion Denial Of Service Vulnerability
  • CVE-2004-2415: Davenport before 0.9.10 allows attackers to cause a denial of service (resource consumption) via (1) a very large XML file or (2) entity expansion attacks.
  • OSVDB ID: 9105: Davenport WebDAV-CIFS Gateway XML DoS
  • SA12337: Davenport WebDAV-CIFS Gateway XML Denial of Service Vulnerability
  • SECTRACK ID: 1011030: Davenport Gateway Lets Remote Users Consume Excessive Resources in Processing XML Documents

Reported:

Aug 23, 2004

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page