~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
Candidate: CVE-2016-10127
PublicDate: 2017-03-03
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10127
 https://github.com/rohe/pysaml2/pull/379
 https://github.com/rohe/pysaml2/commit/6e09a25d9b4b7aa7a506853210a9a14100b8bc9b
 http://www.openwall.com/lists/oss-security/2017/01/10/6
Description:
 PySAML2 allows remote attackers to conduct XML external entity (XXE)
 attacks via a crafted SAML XML request or response.
Ubuntu-Description:
Notes:
Bugs:
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850716
Priority: medium
Discovered-by:
Assigned-to:

Patches_python-pysaml2:
upstream_python-pysaml2: released (3.0.0-5)
precise_python-pysaml2: DNE
precise/esm_python-pysaml2: DNE
trusty_python-pysaml2: DNE
vivid/stable-phone-overlay_python-pysaml2: DNE
vivid/ubuntu-core_python-pysaml2: DNE
xenial_python-pysaml2: needed
yakkety_python-pysaml2: ignored (reached end-of-life)
zesty_python-pysaml2: needed
devel_python-pysaml2: needed