CVE-2009-0217
published 2009-07-14CVE-2009-0217: The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer…
PriorityP335medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
6.35%
92.9th percentile
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.
Affected
113 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | xml_security_for_c | <= 1.7.0 | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| apache | xml_security_for_c | — | — |
| debian | mono | < mono 2.4.2.3+dfsg-1 (bookworm) | mono 2.4.2.3+dfsg-1 (bookworm) |
| debian | xml-security-c | < mono 2.4.2.3+dfsg-1 (bookworm) | mono 2.4.2.3+dfsg-1 (bookworm) |
| debian | xml-security-c | < xml-security-c 1.6.1-6 (bookworm) | xml-security-c 1.6.1-6 (bookworm) |
| debian | xmlsec1 | < mono 2.4.2.3+dfsg-1 (bookworm) | mono 2.4.2.3+dfsg-1 (bookworm) |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-2155: xml-security-c - Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not...
vendor_debian·2013·CVSS 5.0
CVE-2013-2155 [MEDIUM] CVE-2013-2155: xml-security-c - Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not...
Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted length values to the (1) compareBase64StringToRaw, (2) DSIGAlgorithmHandlerDefault, or (3) DSIGAlgorithmHandlerDefault::verify functions.
Scope: local
bookworm: resolved (fixed in 1.6.1-6)
bullseye: resolved (fixed in 1.6.1-6)
forky: resolved (fixed in 1.6.1-6)
sid: resolved (fixed in 1.6.1-6)
trixie: resolved (fixed in 1.6.1-6)
Ubuntu
OpenOffice.org vulnerabilities
vendor_ubuntu·2010-02-24·CVSS 5.0
CVE-2009-0217 [MEDIUM] OpenOffice.org vulnerabilities
Title: OpenOffice.org vulnerabilities
Summary: OpenOffice.org vulnerabilities
It was discovered that the XML HMAC signature system did not
correctly check certain lengths. If an attacker sent a truncated
HMAC, it could bypass authentication, leading to potential privilege
escalation. (CVE-2009-0217)
Sebastian Apelt and Frank Reißner discovered that OpenOffice did not
correctly import XPM and GIF images. If a user were tricked into opening
a specially crafted image, an attacker could execute arbitrary code with
user privileges. (CVE-2009-2949, CVE-2009-2950)
Nicolas Joly discovered that OpenOffice did not correctly handle
certain Word documents. If a user were tricked into opening a specially
crafted document, an attacker could execute arbitrary code with user
privileges. (CVE-2009-3301
Ubuntu
Mono vulnerabilities
vendor_ubuntu·2009-08-26·CVSS 4.3
CVE-2009-0217 [MEDIUM] Mono vulnerabilities
Title: Mono vulnerabilities
Summary: Mono vulnerabilities
It was discovered that the XML HMAC signature system did not correctly
check certain lengths. If an attacker sent a truncated HMAC, it could
bypass authentication, leading to potential privilege escalation.
(CVE-2009-0217)
It was discovered that Mono did not properly escape certain attributes in
the ASP.net class libraries which could result in browsers becoming
vulnerable to cross-site scripting attacks when processing the output. With
cross-site scripting vulnerabilities, if a user were tricked into viewing
server output during a crafted server request, a remote attacker could
exploit this to modify the contents, or steal confidential data (such as
passwords), within the same domain. This issue only affected Ubuntu 8.04
LTS. (C
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2009-08-11·CVSS 5.0
CVE-2009-0217 [MEDIUM] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: OpenJDK vulnerabilities
It was discovered that the XML HMAC signature system did not
correctly check certain lengths. If an attacker sent a truncated
HMAC, it could bypass authentication, leading to potential privilege
escalation. (CVE-2009-0217)
It was discovered that JAR bundles would appear signed if only one element
was signed. If a user were tricked into running a malicious Java applet, a
remote attacker could exploit this to gain access to private information and
potentially run untrusted code. (CVE-2009-1896)
It was discovered that certain variables could leak information. If a
user were tricked into running a malicious Java applet, a remote attacker
could exploit this to gain access to private information and potentially
run untrusted cod
Red Hat
xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass
vendor_redhat·2009-07-14·CVSS 5.0
CVE-2009-0217 [MEDIUM] xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass
xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (H
Debian
CVE-2009-0217: mono - The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendati...
vendor_debian·2009·CVSS 5.0
CVE-2009-0217 [MEDIUM] CVE-2009-0217: mono - The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendati...
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof
GHSA
GHSA-pq9g-7grj-xrm8: Apache Santuario XML Security for C++ (aka xml-security-c) before 1
ghsa_unreviewed·2022-05-13·CVSS 5.0
CVE-2013-2155 [MEDIUM] CWE-20 GHSA-pq9g-7grj-xrm8: Apache Santuario XML Security for C++ (aka xml-security-c) before 1
Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted length values to the (1) compareBase64StringToRaw, (2) DSIGAlgorithmHandlerDefault, or (3) DSIGAlgorithmHandlerDefault::verify functions.
GHSA
Apache XML Security For Java vulnerable to authentication bypass by HMAC truncation
ghsa·2022-05-02
CVE-2009-0217 [MEDIUM] Apache XML Security For Java vulnerable to authentication bypass by HMAC truncation
Apache XML Security For Java vulnerable to authentication bypass by HMAC truncation
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in multiple products.
The Apache XML Security (Java) is affected by the vulnerability published in US-Cert VU #466161. See: http://www.kb.cert.org/vuls/id/466161 for more information. This bug can allow an attacker to bypass authentication by inserting/modifying a small HMAC truncation length parameter in the XML Signature HMAC based SignatureMethod algorithms.
An inexhaustive list of additional affected products includes:
1. the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM;
2. the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2
OSV
Apache XML Security For Java vulnerable to authentication bypass by HMAC truncation
osv·2022-05-02
CVE-2009-0217 [MEDIUM] Apache XML Security For Java vulnerable to authentication bypass by HMAC truncation
Apache XML Security For Java vulnerable to authentication bypass by HMAC truncation
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in multiple products.
The Apache XML Security (Java) is affected by the vulnerability published in US-Cert VU #466161. See: http://www.kb.cert.org/vuls/id/466161 for more information. This bug can allow an attacker to bypass authentication by inserting/modifying a small HMAC truncation length parameter in the XML Signature HMAC based SignatureMethod algorithms.
An inexhaustive list of additional affected products includes:
1. the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM;
2. the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2
OSV
CVE-2013-2155: Apache Santuario XML Security for C++ (aka xml-security-c) before 1
osv·2013-08-20·CVSS 5.0
CVE-2013-2155 [MEDIUM] CVE-2013-2155: Apache Santuario XML Security for C++ (aka xml-security-c) before 1
Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted length values to the (1) compareBase64StringToRaw, (2) DSIGAlgorithmHandlerDefault, or (3) DSIGAlgorithmHandlerDefault::verify functions.
OSV
CVE-2009-0217: The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Devel
osv·2009-07-14·CVSS 5.0
CVE-2009-0217 [MEDIUM] CVE-2009-0217: The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Devel
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0217 xmlsec1, mono, xml-security-c, xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass [epel-5]
bugzilla·2011-04-06·CVSS 5.0
CVE-2009-0217 [MEDIUM] CVE-2009-0217 xmlsec1, mono, xml-security-c, xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass [epel-5]
CVE-2009-0217 xmlsec1, mono, xml-security-c, xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass [epel-5]
epel-5 tracking bug for mono: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Hi Xavier,
Are there any plans to update the version of mono and associaated mono packages in epel for el5? If not should we look at retiring the package(s)?
Regards,
JT
---
I have now retired Mono 1.2 from Epel5.
I recommend to use Mono 4.2 in Epel7.
---
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 1000 days
Bugzilla
CVE-2009-0217 xmlsec1, mono, xml-security-c, xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass
bugzilla·2009-07-15·CVSS 5.0
CVE-2009-0217 [MEDIUM] CVE-2009-0217 xmlsec1, mono, xml-security-c, xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass
CVE-2009-0217 xmlsec1, mono, xml-security-c, xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-0217 to
the following vulnerability:
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; and other products uses a parame
http://blogs.sun.com/security/entry/cert_vulnerability_note_vu_466161http://git.gnome.org/cgit/xmlsec/commit/?id=34b349675af9f72eb822837a8772cc1ead7115c7http://git.gnome.org/cgit/xmlsec/patch/?id=34b349675af9f72eb822837a8772cc1ead7115c7http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.htmlhttp://marc.info/?l=bugtraq&m=125787273209737&w=2http://osvdb.org/55895http://osvdb.org/55907http://secunia.com/advisories/34461http://secunia.com/advisories/35776http://secunia.com/advisories/35852http://secunia.com/advisories/35853http://secunia.com/advisories/35854http://secunia.com/advisories/35855http://secunia.com/advisories/35858http://secunia.com/advisories/36162http://secunia.com/advisories/36176http://secunia.com/advisories/36180http://secunia.com/advisories/36494http://secunia.com/advisories/37300http://secunia.com/advisories/37671http://secunia.com/advisories/37841http://secunia.com/advisories/38567http://secunia.com/advisories/38568http://secunia.com/advisories/38695http://secunia.com/advisories/38921http://secunia.com/advisories/41818http://secunia.com/advisories/60799http://sunsolve.sun.com/search/document.do?assetkey=1-21-125136-16-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-263429-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-269208-1http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020710.1-1http://svn.apache.org/viewvc?revision=794013&view=revisionhttp://www-01.ibm.com/support/docview.wss?rs=180&context=SSEQTP&dc=D400&uid=swg24023545&loc=en_US&cs=UTF-8&lang=en&rss=ct180webspherehttp://www-01.ibm.com/support/docview.wss?rs=180&context=SSEQTP&dc=D400&uid=swg24023723&loc=en_US&cs=UTF-8&lang=en&rss=ct180webspherehttp://www-01.ibm.com/support/docview.wss?rs=180&uid=swg21384925http://www.aleksey.com/xmlsec/http://www.debian.org/security/2010/dsa-1995http://www.gentoo.org/security/en/glsa/glsa-201408-19.xmlhttp://www.kb.cert.org/vuls/id/466161http://www.kb.cert.org/vuls/id/MAPG-7TSKXQhttp://www.kb.cert.org/vuls/id/WDON-7TY529http://www.mandriva.com/security/advisories?name=MDVSA-2009:209http://www.mono-project.com/Vulnerabilitieshttp://www.openoffice.org/security/cves/CVE-2009-0217.htmlhttp://www.oracle.com/technetwork/topics/security/cpujul2009-091332.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.htmlhttp://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.htmlhttp://www.redhat.com/support/errata/RHSA-2009-1694.htmlhttp://www.securityfocus.com/bid/35671http://www.securitytracker.com/id?1022561http://www.securitytracker.com/id?1022567http://www.securitytracker.com/id?1022661http://www.ubuntu.com/usn/USN-903-1http://www.us-cert.gov/cas/techalerts/TA09-294A.htmlhttp://www.us-cert.gov/cas/techalerts/TA10-159B.htmlhttp://www.vupen.com/english/advisories/2009/1900http://www.vupen.com/english/advisories/2009/1908http://www.vupen.com/english/advisories/2009/1909http://www.vupen.com/english/advisories/2009/1911http://www.vupen.com/english/advisories/2009/2543http://www.vupen.com/english/advisories/2009/3122http://www.vupen.com/english/advisories/2010/0366http://www.vupen.com/english/advisories/2010/0635http://www.w3.org/2008/06/xmldsigcore-errata.html#e03http://www.w3.org/QA/2009/07/hmac_truncation_in_xml_signatu.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=511915https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-041https://issues.apache.org/bugzilla/show_bug.cgi?id=47526https://issues.apache.org/bugzilla/show_bug.cgi?id=47527https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10186https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7158https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8717https://rhn.redhat.com/errata/RHSA-2009-1200.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1201.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1428.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1636.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1637.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1649.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1650.htmlhttps://usn.ubuntu.com/826-1/https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00310.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00325.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00494.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-August/msg00505.htmlhttp://blogs.sun.com/security/entry/cert_vulnerability_note_vu_466161http://git.gnome.org/cgit/xmlsec/commit/?id=34b349675af9f72eb822837a8772cc1ead7115c7http://git.gnome.org/cgit/xmlsec/patch/?id=34b349675af9f72eb822837a8772cc1ead7115c7http://lists.apple.com/archives/security-announce/2009/Sep/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00005.htmlhttp://marc.info/?l=bugtraq&m=125787273209737&w=2http://osvdb.org/55895http://osvdb.org/55907http://secunia.com/advisories/34461http://secunia.com/advisories/35776http://secunia.com/advisories/35852http://secunia.com/advisories/35853http://secunia.com/advisories/35854
+ 72 more references
2009-07-14
Published