CVE-2019-9628
Summary
| CVE | CVE-2019-9628 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-11 20:29:00 UTC |
| Updated | 2022-04-18 17:32:00 UTC |
| Description | The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type. |
Risk And Classification
Problem Types: CWE-755
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.10 | All | All | All |
| Operating System | Opensuse | Leap | 15.0 | All | All | All |
| Operating System | Opensuse | Leap | 42.3 | All | All | All |
| Operating System | Opensuse | Leap | 15.0 | All | All | All |
| Operating System | Opensuse | Leap | 42.3 | All | All | All |
| Application | Xmltooling Project | Xmltooling | All | All | All | All |
| Application | Xmltooling Project | Xmltooling | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityAdvisories - Service Provider 3 - Shibboleth Wiki | MISC | wiki.shibboleth.net | Third Party Advisory |
| shibboleth.net/community/advisories/secadv_20190311.txt | MISC | shibboleth.net | Third Party Advisory |
| [security-announce] openSUSE-SU-2019:1235-1: moderate: Security update f | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| Bug #1819912 “CVE-2019-9628 XML parser class fails to trap excep...” : Bugs : xmltooling package : Ubuntu | MISC | bugs.launchpad.net | Issue Tracking, Third Party Advisory |
| CVE-2019-9628 XMLTooling Library Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| USN-3921-1: XMLTooling vulnerability | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| [security-announce] openSUSE-SU-2019:1276-1: moderate: Security update f | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.