Bug 1614632 - xml-security-c: Improper validation of KeyInfo hints allows for denial of service via crafted XML
Summary: xml-security-c: Improper validation of KeyInfo hints allows for denial of ser...
Keywords:
Status: CLOSED DUPLICATE of bug 1612388
Alias: None
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1612389 1612390 1614634 1614635
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-08-10 06:04 UTC by Sam Fowler
Modified: 2019-09-29 14:47 UTC (History)
3 users (show)

Fixed In Version: xml-security-c 2.0.1
Clone Of:
Environment:
Last Closed: 2018-08-10 06:16:44 UTC
Embargoed:


Attachments (Terms of Use)

Description Sam Fowler 2018-08-10 06:04:47 UTC
It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer dereferences when processing malformed XML data.


Upstream Bug:

https://issues.apache.org/jira/projects/SANTUARIO/issues/SANTUARIO-491


Upstream Patch:

https://svn.apache.org/viewvc?view=revision&revision=1837240

Comment 1 Sam Fowler 2018-08-10 06:09:10 UTC
Created xml-security-c tracking bugs for this issue:

Affects: epel-all [bug 1614635]
Affects: fedora-all [bug 1614634]

Comment 2 Sam Fowler 2018-08-10 06:16:44 UTC

*** This bug has been marked as a duplicate of bug 1612388 ***


Note You need to log in before you can comment on or make changes to this bug.