CVE-2013-1864: Ekiga

Medium severity, CVSS 4.3. EPSS: 2.9% chance of exploitation in the next 30 days.

The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXML document containing a large number of nested entity references, aka a "billion laughs attack."

Affected products

  • Ekiga Ekiga: up to and including 4.0.0
  • Opalvoip Portable Tool Library: version 2.10.1 only; version 2.10.2 only; version 2.10.7 only; version 2.10.9 only
  • Suse Suse Linux Enterprise Desktop: version 11.0 only
  • Suse Suse Linux Enterprise Software Development Kit: version 11.0 only

Published 2014-05-23. Last modified 2026-06-16.