[ubuntu/lucid-security] libxml-security-java 1.4.3-2ubuntu0.1 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Tue Nov 12 17:37:11 UTC 2013


libxml-security-java (1.4.3-2ubuntu0.1) lucid-security; urgency=low

  * SECURITY UPDATE: XML signature spoofing via CanonicalizationMethod
    parameter
    - src/org/jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java:
      don't allow non-standard c14n method.
    - http://svn.apache.org/viewvc?view=revision&revision=1493772
    - CVE-2013-2172

Date: 2013-09-10 16:07:15.575169+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/lucid/+source/libxml-security-java/1.4.3-2ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Lucid-changes mailing list