Typical severity: High. Likelihood of attack: Low. An attacker exploits the underlying complexity of a data structure that allows for both signed and unsigned content, to cause unsigned data to be processed as though it were signed data.
Ensure the application is fully patched and does not allow the processing of unsigned data as if it is signed data.