Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-0486

Опубликовано: 13 янв. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.4
CVSS3: 6.5

Описание

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

1.6.3-1
devel

not-affected

1.6.3-1
esm-apps/bionic

not-affected

1.6.3-1
esm-apps/xenial

released

1.5.6-2ubuntu0.1
esm-infra-legacy/trusty

released

1.5.3-2+deb8u2build0.14.04.1
precise/esm

DNE

trusty

released

1.5.3-2+deb8u2build0.14.04.1
trusty/esm

released

1.5.3-2+deb8u2build0.14.04.1
upstream

released

1.6.3

Показывать по

EPSS

Процентиль: 76%
0.00921
Низкий

6.4 Medium

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.7
redhat
около 8 лет назад

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

CVSS3: 6.5
nvd
около 8 лет назад

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

CVSS3: 6.5
debian
около 8 лет назад

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Pr ...

suse-cvrf
около 8 лет назад

Security update for xmltooling

suse-cvrf
около 8 лет назад

Security update for xmltooling

EPSS

Процентиль: 76%
0.00921
Низкий

6.4 Medium

CVSS2

6.5 Medium

CVSS3