CAPEC 197 Exponential Data Expansion

Draft Detailed High Risk
Severity Medium

Description

An adversary submits data to a target application which contains nested exponential data expansion to produce excessively large output. Many data format languages allow the definition of macro-like structures that can be used to simplify the creation of complex structures. However, this capability can be abused to create excessive demands on a processor's CPU and memory. A small number of nested expansions can result in an exponential growth in demands on memory.

Attack Execution Flow

3

Mitigations

2

Consequences

Relationships

Resources Required

1