LWN.net Logo

xml-security-c: multiple vulnerabilities

Package(s):xml-security-c CVE #(s):CVE-2013-2153 CVE-2013-2154 CVE-2013-2155 CVE-2013-2156
Created:June 19, 2013 Updated:June 28, 2013
Description: From the Debian advisory:

CVE-2013-2153: The implementation of XML digital signatures in the Santuario-C++ library is vulnerable to a spoofing issue allowing an attacker to reuse existing signatures with arbitrary content.

CVE-2013-2154: A stack overflow, possibly leading to arbitrary code execution, exists in the processing of malformed XPointer expressions in the XML Signature Reference processing code.

CVE-2013-2155: A bug in the processing of the output length of an HMAC-based XML Signature would cause a denial of service when processing specially chosen input.

CVE-2013-2156: A heap overflow exists in the processing of the PrefixList attribute optionally used in conjunction with Exclusive Canonicalization, potentially allowing arbitrary code execution.

Alerts:
Debian DSA-2710-1 2013-06-18
Debian DSA-2717-1 2013-06-28
Mageia MGASA-2013-0193 2013-07-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds