Posted by Colm O hEigeartaigh on Sep 30 Severity: important Affected versions: - Apache WSS4J 4.0.0 before 4.0.2 - Apache WSS4J 3.0.0 before 3.0.6 - Apache WSS4J before 2.4.4 Description: An integer overflow in WSS4J's DER bounds check lets an oversized allocation pass validation. An unauthenticated attacker can send a SOAP message carrying an X.509 certificate whose SubjectKeyIdentifier extension declares a length of 0x7FFFFFFF; WSS4J decodes this while resolving the...

Read the full article at oss-security →