[ubuntu/cosmic-updates] xmltooling 3.0.2-1ubuntu1.1 (Accepted)
Ubuntu Archive Robot
cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Tue Mar 26 13:28:18 UTC 2019
xmltooling (3.0.2-1ubuntu1.1) cosmic-security; urgency=high
* SECURITY UPDATE: uncaught exception on malformed XML declaration
Invalid data in the XML declaration causes an exception of a type that
was not handled properly in the parser class and propagates an
unexpected exception type.
This generally manifests as a crash in the calling code, which in the
Service Provider software's case is usually the shibd daemon process,
but can be Apache in some cases. Note that the crash occurs prior to
evaluation of a message's authenticity, so can be exploited by an
untrusted attacker.
- debian/patches/CVE-2019-9628.patch
- CVE-2019-9628
- https://shibboleth.net/community/advisories/secadv_20190311.txt
- LP: #1819912
Date: 2019-03-21 17:51:12.340769+00:00
Changed-By: Etienne Dysli Metref <etienne.dysli-metref at switch.ch>
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/+source/xmltooling/3.0.2-1ubuntu1.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Cosmic-changes
mailing list