* [2890d0c] New patches fixing CVE-2018-0489: additional data forgery flaws.
These flaws allow for changes to an XML document that do not break a
digital signature but alter the user data passed through to applications
enabling impersonation attacks and exposure of protected information. https://shibboleth.net/community/advisories/secadv_20180227.txt https://issues.shibboleth.net/jira/browse/CPPXT-128
The Add-disallowDoctype-to-parser-configuration.patch is not effective
under Xerces 3.1 in jessie, but provides more generic protection under
Xerces 3.2 against issues like CVE-2018-0486. It's included here for
completeness and to avoid a conflict applying the CVE-2018-0489 patch.
-- Steve Beattie <email address hidden> Tue, 20 Mar 2018 15:21:30 -0700
This bug was fixed in the package xmltooling - 1.5.3-2+ deb8u3build0. 14.04.1
--------------- 2+deb8u3build0. 14.04.1) trusty-security; urgency=medium
xmltooling (1.5.3-
* fake sync from Debian (LP: #1752306)
xmltooling (1.5.3-2+deb8u3) jessie-security; urgency=high
* [2890d0c] New patches fixing CVE-2018-0489: additional data forgery flaws. /shibboleth. net/community/ advisories/ secadv_ 20180227. txt /issues. shibboleth. net/jira/ browse/ CPPXT-128 type-to- parser- configuration. patch is not effective
These flaws allow for changes to an XML document that do not break a
digital signature but alter the user data passed through to applications
enabling impersonation attacks and exposure of protected information.
https:/
https:/
The Add-disallowDoc
under Xerces 3.1 in jessie, but provides more generic protection under
Xerces 3.2 against issues like CVE-2018-0486. It's included here for
completeness and to avoid a conflict applying the CVE-2018-0489 patch.
-- Steve Beattie <email address hidden> Tue, 20 Mar 2018 15:21:30 -0700