#VU71585 Out-of-bounds write in xstream - CVE-2022-40151
Published: January 26, 2023 / Updated: January 26, 2023
xstream
XStream
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing untrusted input in the Woodstox XML parser. A remote attacker can pass a specially crafted input to the parser, trigger an out-of-bounds write and execute arbitrary code on the target system.