Back to search
CVE-2018-0486
Published: Jan 13, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.
| Vendor | Product | Versions |
|---|---|---|
n/a | XMLTooling-C before 1.6.3 | affected XMLTooling-C before 1.6.3 |
References
DSA-4085
vendor-advisory
x_refsource_DEBIAN
https://shibboleth.net/community/advisories/secadv_20180112.txt
x_refsource_MISC
[debian-lts-announce] 20180114 [SECURITY] [DLA 1242-1] xmltooling security update
mailing-list
x_refsource_MLIST
1040177
vdb-entry
x_refsource_SECTRACK
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now