CVE-2018-0486
Summary
| CVE | CVE-2018-0486 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-01-13 18:29:00 UTC |
| Updated | 2018-02-15 18:24:00 UTC |
| Description | Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD. |
Risk And Classification
Problem Types: CWE-347
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Shibboleth | Xmltooling-c | All | All | All | All |
| Application | Shibboleth | Xmltooling-c | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| shibboleth.net/community/advisories/secadv_20180112.txt | MISC | shibboleth.net | Vendor Advisory |
| [SECURITY] [DSA 4085-1] xmltooling security update | MISC | lists.debian.org | Mailing List, Third Party Advisory |
| Shibboleth Service Provider Lets Remote Users Modify User Attribute Data on the Target System - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| [SECURITY] [DLA 1242-1] xmltooling security update | MLIST | lists.debian.org | Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-4085-1 xmltooling | DEBIAN | www.debian.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.