~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
Candidate: CVE-2013-6440
PublicDate: 2014-02-14
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6440
 http://shibboleth.net/community/advisories/secadv_20131213.txt
 http://blog.sendsafely.com/post/69590974866/web-based-single-sign-on-and-the-dangers-of-saml-xml
Description:
 The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and
 (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the
 expandEntityReferences property to true, which allows remote attackers to
 conduct XML external entity (XXE) attacks via a crafted XML DOCTYPE
 declaration.
Ubuntu-Description:
Notes:
Bugs:
Priority: medium
Discovered-by:
Assigned-to:

Patches_opensaml2:
upstream_opensaml2: needs-triage
lucid_opensaml2: ignored (reached end-of-life)
precise_opensaml2: ignored (reached end-of-life)
precise/esm_opensaml2: DNE (precise was needed)
quantal_opensaml2: ignored (reached end-of-life)
raring_opensaml2: ignored (reached end-of-life)
saucy_opensaml2: ignored (reached end-of-life)
trusty_opensaml2: needed
utopic_opensaml2: ignored (reached end-of-life)
vivid_opensaml2: ignored (reached end-of-life)
vivid/stable-phone-overlay_opensaml2: DNE
vivid/ubuntu-core_opensaml2: DNE
wily_opensaml2: ignored (reached end-of-life)
xenial_opensaml2: needed
yakkety_opensaml2: ignored (reached end-of-life)
zesty_opensaml2: needed
devel_opensaml2: needed