[ubuntu/lucid-updates] libxml-security-java 1.4.3-2ubuntu0.1 (Accepted)
Ubuntu Archive Robot
cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Tue Nov 12 17:58:07 UTC 2013
libxml-security-java (1.4.3-2ubuntu0.1) lucid-security; urgency=low
* SECURITY UPDATE: XML signature spoofing via CanonicalizationMethod
parameter
- src/org/jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java:
don't allow non-standard c14n method.
- http://svn.apache.org/viewvc?view=revision&revision=1493772
- CVE-2013-2172
Date: 2013-09-10 16:07:15.575169+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/lucid/+source/libxml-security-java/1.4.3-2ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Lucid-changes
mailing list