CVE-2011-2516
published 2011-07-11CVE-2011-2516: Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows…
PriorityP428medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
7.72%
93.9th percentile
Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | xml_security_for_c | — | — |
| debian | xml-security-c | < xml-security-c 1.6.1-1 (bookworm) | xml-security-c 1.6.1-1 (bookworm) |
| shibboleth | shibboleth-sp | <= 2.4.2 | — |
| shibboleth | shibboleth-sp | — | — |
| shibboleth | shibboleth-sp | — | — |
| shibboleth | shibboleth-sp | — | — |
| shibboleth | shibboleth-sp | — | — |
| shibboleth | shibboleth-sp | — | — |
| shibboleth | shibboleth-sp | — | — |
| shibboleth | shibboleth-sp | — | — |
| shibboleth | shibboleth-sp | — | — |
| shibboleth | shibboleth-sp | — | — |
| shibboleth | shibboleth-sp | — | — |
| shibboleth | shibboleth-sp | — | — |
| shibboleth | shibboleth-sp | — | — |
| shibboleth | shibboleth-sp | — | — |
| shibboleth | shibboleth-sp | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2jmv-v2x6-mmv8: Off-by-one error in the XML signature feature in Apache XML Security for C++ 1
ghsa_unreviewed·2022-05-13
CVE-2011-2516 [MEDIUM] GHSA-2jmv-v2x6-mmv8: Off-by-one error in the XML signature feature in Apache XML Security for C++ 1
Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
OSV
CVE-2011-2516: Off-by-one error in the XML signature feature in Apache XML Security for C++ 1
osv·2011-07-11·CVSS 5.0
CVE-2011-2516 [MEDIUM] CVE-2011-2516: Off-by-one error in the XML signature feature in Apache XML Security for C++ 1
Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
Debian
CVE-2011-2516: xml-security-c - Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6...
vendor_debian·2011·CVSS 5.0
CVE-2011-2516 [MEDIUM] CVE-2011-2516: xml-security-c - Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6...
Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.6.1-1)
bullseye: resolved (fixed in 1.6.1-1)
forky: resolved (fixed in 1.6.1-1)
sid: resolved (fixed in 1.6.1-1)
trixie: resolved (fixed in 1.6.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2516 xml-security-c: Stack-based buffer overflows when creating or verifying XML Signatures with RSA keys of sizes >= 8192 bits
bugzilla·2011-07-07·CVSS 5.0
CVE-2011-2516 [MEDIUM] CVE-2011-2516 xml-security-c: Stack-based buffer overflows when creating or verifying XML Signatures with RSA keys of sizes >= 8192 bits
CVE-2011-2516 xml-security-c: Stack-based buffer overflows when creating or verifying XML Signatures with RSA keys of sizes >= 8192 bits
Stack-based buffer overflow flaws were found in the way xml-security-c, a C++ implementation of the XML Digital Signature specification, performed creation and verification of XML Signatures, when large RSA keys (length >= 8192) were used. A remote attacker, using sufficiently long RSA key, could use this flaw to cause an application linked against the xml-security-c library to crash (denial of service), or, potentially, it to execute arbitrary code with the privileges of the user running the application.
References:
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=632973
[2] http://santuario.apache.org/secadv/CVE-2011-2516.txt
[3] https://issues.ap
Bugzilla
CVE-2011-2516 xml-security-c: Stack-based buffer overflows when creating or verifying XML Signatures with RSA keys of sizes >= 8192 bits [fedora-all]
bugzilla·2011-07-07·CVSS 5.0
CVE-2011-2516 [MEDIUM] CVE-2011-2516 xml-security-c: Stack-based buffer overflows when creating or verifying XML Signatures with RSA keys of sizes >= 8192 bits [fedora-all]
CVE-2011-2516 xml-security-c: Stack-based buffer overflows when creating or verifying XML Signatures with RSA keys of sizes >= 8192 bits [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/update
Bugzilla
CVE-2011-2516 xml-security-c: Stack-based buffer overflows when creating or verifying XML Signatures with RSA keys of sizes >= 8192 bits [epel-all]
bugzilla·2011-07-07·CVSS 5.0
CVE-2011-2516 [MEDIUM] CVE-2011-2516 xml-security-c: Stack-based buffer overflows when creating or verifying XML Signatures with RSA keys of sizes >= 8192 bits [epel-all]
CVE-2011-2516 xml-security-c: Stack-based buffer overflows when creating or verifying XML Signatures with RSA keys of sizes >= 8192 bits [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/
http://lists.fedoraproject.org/pipermail/package-announce/2011-July/063159.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/063229.htmlhttp://santuario.apache.org/secadv/CVE-2011-2516.txthttp://secunia.com/advisories/45151http://secunia.com/advisories/45191http://secunia.com/advisories/45198http://secunia.com/advisories/45491http://shibboleth.internet2.edu/secadv/secadv_20110706.txthttp://www.debian.org/security/2011/dsa-2277http://www.securityfocus.com/archive/1/518756/100/0/threadedhttp://www.securityfocus.com/bid/48611http://www.securitytracker.com/id?1025755https://exchange.xforce.ibmcloud.com/vulnerabilities/68420https://issues.apache.org/jira/browse/SANTUARIO-271https://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3%40%3Ccommits.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/r1c07a561426ec5579073046ad7f4207cdcef452bb3100abaf908e0cd%40%3Ccommits.santuario.apache.org%3Ehttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/063159.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/063229.htmlhttp://santuario.apache.org/secadv/CVE-2011-2516.txthttp://secunia.com/advisories/45151http://secunia.com/advisories/45191http://secunia.com/advisories/45198http://secunia.com/advisories/45491http://shibboleth.internet2.edu/secadv/secadv_20110706.txthttp://www.debian.org/security/2011/dsa-2277http://www.securityfocus.com/archive/1/518756/100/0/threadedhttp://www.securityfocus.com/bid/48611http://www.securitytracker.com/id?1025755https://exchange.xforce.ibmcloud.com/vulnerabilities/68420https://issues.apache.org/jira/browse/SANTUARIO-271https://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3%40%3Ccommits.santuario.apache.org%3Ehttps://lists.apache.org/thread.html/r1c07a561426ec5579073046ad7f4207cdcef452bb3100abaf908e0cd%40%3Ccommits.santuario.apache.org%3E
2011-07-11
Published