Description
CiphertextHeader.java in Cryptacular 1.2.3, as used in Apereo CAS and other products, allows attackers to trigger excessive memory allocation during a decode operation, because the nonce array length associated with "new byte" may depend on untrusted input within the header of encoded data.
Remediation
References
Related Vulnerabilities
WordPress Plugin Duplicator-WordPress Migration Remote Code Execution (1.2.40)
WordPress Plugin Limit Attempts by BestWebSoft Cross-Site Scripting (1.1.7)
qdPM Sensitive Information Disclosure Vulnerability (CVE-2015-3881)
WordPress Plugin Accept Stripe Donation-AidWP Cross-Site Request Forgery (3.1.5)