CVE-2018-0489
Summary
| CVE | CVE-2018-0489 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-27 15:29:00 UTC |
| Updated | 2018-03-23 15:18:00 UTC |
| Description | Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML data. NOTE: this issue exists because of an incomplete fix for CVE-2018-0486. |
Risk And Classification
Problem Types: CWE-347
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Arubanetworks | Clearpass | All | All | All | All |
| Application | Arubanetworks | Clearpass | All | All | All | All |
| Application | Arubanetworks | Clearpass | All | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Shibboleth | Xmltooling-c | All | All | All | All |
| Application | Shibboleth | Xmltooling-c | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| shibboleth.net/community/advisories/secadv_20180227.txt | CONFIRM | shibboleth.net | Patch, Vendor Advisory |
| Shibboleth Service Provider Flaw Lets Remote Users Modify User Data on the Target System - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Malformed Request | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| [SECURITY] [DLA 1296-1] xmltooling security update | MLIST | lists.debian.org | Issue Tracking |
| www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-003.txt | CONFIRM | www.arubanetworks.com | Third Party Advisory |
| Debian -- Security Information -- DSA-4126-1 xmltooling | DEBIAN | www.debian.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.