Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-0486

Опубликовано: 13 янв. 2018
Источник: debian

Описание

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xmltoolingfixed1.6.3-1package
xmltoolingfixed1.6.0-4+deb9u1stretchpackage

Примечания

  • https://shibboleth.net/community/advisories/secadv_20180112.txt

  • Fixed upstream in 1.6.3 to workaround bug independent of if parser already

  • disallow DTD use.

  • https://issues.shibboleth.net/jira/browse/CPPXT-127

  • https://git.shibboleth.net/view/?p=cpp-xmltooling.git;a=commit;h=a02314e96d6746d29c5697b504d37f2e04a6e6cd

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 8 лет назад

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

CVSS3: 8.7
redhat
около 8 лет назад

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

CVSS3: 6.5
nvd
около 8 лет назад

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

suse-cvrf
около 8 лет назад

Security update for xmltooling

suse-cvrf
около 8 лет назад

Security update for xmltooling