Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xmltooling | Jan 13, 2018 | Jan 12, 2018 |
| Freebsd | — | Upgrade xerces-c3Upgrade xmltooling | Jan 13, 2018 | Jan 12, 2018 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 9.0R1Update Pulse Connect Secure to version 8.3R6Update Pulse Connect Secure to version 8.1R14 | Oct 28, 2020 | Jan 13, 2018 |
| Suse | — | Upgrade xmltooling-schemasUpgrade libxmltooling-lite9Upgrade libxmltooling7Upgrade libxmltooling6Upgrade libxmltooling9Upgrade libxmltooling-devel | Jan 20, 2018 | Jan 12, 2018 |
| Ubuntu | — | Upgrade xmltooling | Nov 19, 2024 | Jan 13, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub