<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent changes to 16: Denial of Service vulnerability (infinite loop) while parsing malicious XML files</title><link>https://sourceforge.net/p/ezxml/bugs/16/</link><description>Recent changes to 16: Denial of Service vulnerability (infinite loop) while parsing malicious XML files</description><atom:link href="https://sourceforge.net/p/ezxml/bugs/16/feed.rss" rel="self"/><language>en</language><lastBuildDate>Mon, 25 Oct 2021 09:16:13 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/ezxml/bugs/16/feed.rss" rel="self" type="application/rss+xml"/><item><title>#16 Denial of Service vulnerability (infinite loop) while parsing malicious XML files</title><link>https://sourceforge.net/p/ezxml/bugs/16/?limit=25#6f3f</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;For me, this issue is resolved by the fix for &lt;a class="" href="https://sourceforge.net/p/ezxml/bugs/26/"&gt;bug 26&lt;/a&gt;.&lt;br/&gt;
Check my &lt;a class="" href="https://sourceforge.net/p/ezxml/bugs/26/#7b82"&gt;comment&lt;/a&gt; there.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Egbert Eich</dc:creator><pubDate>Mon, 25 Oct 2021 09:16:13 -0000</pubDate><guid>https://sourceforge.net26ed8421ee9902dbed1b591c281c80c54b7c2233</guid></item><item><title>Denial of Service vulnerability (infinite loop) while parsing malicious XML files</title><link>https://sourceforge.net/p/ezxml/bugs/16/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;A maliciously crafted XML file triggers an infinite loop while parsing this file using one of ezxml_parse functions.&lt;br/&gt;
The loop is located inside the ezxml_decode function and incorrect handling of XML entities leads to inflate processed strings.&lt;br/&gt;
In the loop consecutive memory allocations are performed rapidly increasing memory usage until reaching memory limits or crashing the execution environment.&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">CVE Reporting</dc:creator><pubDate>Sun, 29 Dec 2019 16:15:22 -0000</pubDate><guid>https://sourceforge.net6e59bb6ef5f1efbbcfeb5a6a48ad240f3af58cc7</guid></item></channel></rss>