Back to search
CVE-2011-2516
Published: Jul 11, 2011
Modified: Aug 6, 2024
PUBLISHED
Description
Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
DSA-2277
vendor-advisory
x_refsource_DEBIAN
45491
third-party-advisory
x_refsource_SECUNIA
45151
third-party-advisory
x_refsource_SECUNIA
20110707 Security Advisory: CVE-2011-2516
mailing-list
x_refsource_BUGTRAQ
apache-xml-dos(68420)
vdb-entry
x_refsource_XF
https://issues.apache.org/jira/browse/SANTUARIO-271
x_refsource_CONFIRM
http://santuario.apache.org/secadv/CVE-2011-2516.txt
x_refsource_CONFIRM
FEDORA-2011-9501
vendor-advisory
x_refsource_FEDORA
45198
third-party-advisory
x_refsource_SECUNIA
45191
third-party-advisory
x_refsource_SECUNIA
http://shibboleth.internet2.edu/secadv/secadv_20110706.txt
x_refsource_CONFIRM
1025755
vdb-entry
x_refsource_SECTRACK
FEDORA-2011-9494
vendor-advisory
x_refsource_FEDORA
48611
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now