The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXML document containing a large number of nested entity references, aka a "billion laughs attack."
| Software | From | Fixed in |
|---|---|---|
| opalvoip / portable_tool_library | 2.10.1 | 2.10.1.x |
| opalvoip / portable_tool_library | 2.10.9 | 2.10.9.x |
| opalvoip / portable_tool_library | 2.10.7 | 2.10.7.x |
| opalvoip / portable_tool_library | 2.10.2 | 2.10.2.x |
| ekiga / ekiga | - | 4.0.0.x |
| suse / suse_linux_enterprise_software_development_kit | 11.0-sp3 | 11.0-sp3.x |
| suse / suse_linux_enterprise_desktop | 11.0-sp3 | 11.0-sp3.x |