CVE Database
/

CVE-2013-2172

Back to search

CVE-2013-2172

Published: Aug 20, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2013:1219
vendor-advisory
x_refsource_REDHAT
54019
third-party-advisory
x_refsource_SECUNIA
RHSA-2013:1218
vendor-advisory
x_refsource_REDHAT
RHSA-2013:1209
vendor-advisory
x_refsource_REDHAT
USN-2028-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2013:1217
vendor-advisory
x_refsource_REDHAT
RHSA-2013:1437
vendor-advisory
x_refsource_REDHAT
RHSA-2013:1207
vendor-advisory
x_refsource_REDHAT
RHSA-2013:1375
vendor-advisory
x_refsource_REDHAT
RHSA-2014:0212
vendor-advisory
x_refsource_REDHAT
RHSA-2013:1853
vendor-advisory
x_refsource_REDHAT
RHSA-2013:1208
vendor-advisory
x_refsource_REDHAT
RHSA-2013:1220
vendor-advisory
x_refsource_REDHAT
60846
vdb-entry
x_refsource_BID
94651
vdb-entry
x_refsource_OSVDB
DSA-3065
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now