CVE-2016-10149
published 2017-03-24CVE-2016-10149: XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
PriorityP350high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
5.02%
91.4th percentile
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | python-pysaml2 | < python-pysaml2 3.0.0-5 (bookworm) | python-pysaml2 3.0.0-5 (bookworm) |
| pysaml2_project | pysaml2 | <= 4.4.0 | — |
| pysaml2_project | pysaml2 | >= 0 < 4.5.0 | 4.5.0 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
PySAML2 vulnerability
vendor_ubuntu·2017-08-24
CVE-2016-10149 PySAML2 vulnerability
Title: PySAML2 vulnerability
Summary: The system could be made to expose sensitive information.
It was discovered that PySAML2 incorrectly handled certain
SAML XML requests and responses. A remote attacker could use
this issue to read arbitrary files.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-pysaml2: Entity expansion issue
vendor_redhat·2016-10-31·CVSS 7.5
CVE-2016-10149 [HIGH] CWE-776 python-pysaml2: Entity expansion issue
python-pysaml2: Entity expansion issue
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
An XML entity expansion vulnerability was found in python-pysaml2. A remote attacker could send a crafted request which would cause denial of service through resource exhaustion.
Package: python-pysaml2 (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Will not fix
Package: python-pysaml2 (Red Hat OpenStack Platform 11 (Ocata)) - Not affected
Debian
CVE-2016-10149: python-pysaml2 - XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remo...
vendor_debian·2016·CVSS 7.5
CVE-2016-10149 [HIGH] CVE-2016-10149: python-pysaml2 - XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remo...
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
Scope: local
bookworm: resolved (fixed in 3.0.0-5)
bullseye: resolved (fixed in 3.0.0-5)
forky: resolved (fixed in 3.0.0-5)
sid: resolved (fixed in 3.0.0-5)
trixie: resolved (fixed in 3.0.0-5)
OSV
Pysaml2 does not sanitize XML responses
osv·2018-07-16
CVE-2016-10149 [HIGH] Pysaml2 does not sanitize XML responses
Pysaml2 does not sanitize XML responses
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
GHSA
Pysaml2 does not sanitize XML responses
ghsa·2018-07-16
CVE-2016-10149 [HIGH] CWE-611 Pysaml2 does not sanitize XML responses
Pysaml2 does not sanitize XML responses
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
OSV
CVE-2016-10149: XML External Entity (XXE) vulnerability in PySAML2 4
osv·2017-03-24·CVSS 7.5
CVE-2016-10149 [HIGH] CVE-2016-10149: XML External Entity (XXE) vulnerability in PySAML2 4
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10149 exim: Remote command execution in deliver_message() function in /src/deliver.c
bugzilla·2019-05-29·CVSS 9.8
CVE-2019-10149 [CRITICAL] CVE-2019-10149 exim: Remote command execution in deliver_message() function in /src/deliver.c
CVE-2019-10149 exim: Remote command execution in deliver_message() function in /src/deliver.c
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
References:
https://www.openwall.com/lists/oss-security/2019/06/04/1
https://exim.org/static/doc/security/CVE-2019-10149.txt
Discussion:
Acknowledgments:
Name: Qualys Research Labs
---
As per the reporter:
"Exim is vulnerable by default since version 4.87 (released on April 6,2016), when #ifdef EXPERIMENTAL_EVENT became #ifndef DISABLE_EVENT; and
older versions may also be vulnerable if EXPERIMENTAL_EVENT was enabled manually. Surprisingly, this vulnerability was fixed in version 4.92
(released on Februar
Bugzilla
CVE-2016-10149 python-pysaml2: various flaws [fedora-all]
bugzilla·2017-01-23·CVSS 9.0
CVE-2016-10149 [CRITICAL] CVE-2016-10149 python-pysaml2: various flaws [fedora-all]
CVE-2016-10149 python-pysaml2: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
o
Bugzilla
CVE-2016-10149 python-pysaml2: Entity expansion issue
bugzilla·2017-01-23·CVSS 7.5
CVE-2016-10149 [HIGH] CVE-2016-10149 python-pysaml2: Entity expansion issue
CVE-2016-10149 python-pysaml2: Entity expansion issue
An entity expansion vulnerability was found in python-pysaml2.
Upstream patch:
https://github.com/rohe/pysaml2/commit/6e09a25d9b4b7aa7a506853210a9a14100b8bc9b
References:
http://seclists.org/oss-sec/2017/q1/140
Discussion:
Created python-pysaml2 tracking bugs for this issue:
Affects: fedora-all [bug 1415563]
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 10.0 (Newton)
Via RHSA-2017:0938 https://access.redhat.com/errata/RHSA-2017:0938
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 9.0 (Mitaka)
Via RHSA-2017:0937 https://access.redhat.com/errata/RHSA-2017:0937
---
This issue has been addressed in the following products:
Red Hat OpenStack P
Bugzilla
CVE-2016-10127 python-pysaml2: Vulnerable to XML external entity attack
bugzilla·2017-01-10·CVSS 9.0
CVE-2016-10127 [CRITICAL] CVE-2016-10127 python-pysaml2: Vulnerable to XML external entity attack
CVE-2016-10127 python-pysaml2: Vulnerable to XML external entity attack
It was found that python-pysaml2 is vulnerable to an XML external entity attack. python-pysaml2 does not sanitize SAML XML requests or responses.
References:
http://seclists.org/oss-sec/2017/q1/50
https://bugs.debian.org/850716
Upstream bug:
https://github.com/rohe/pysaml2/issues/366
Proposed patch (! actually fixes Bug 1415710):
https://github.com/rohe/pysaml2/pull/379
Discussion:
CVE assignment:
http://seclists.org/oss-sec/2017/q1/58
---
John, one note for OpenStack builds:
https://github.com/openstack/requirements/blob/master/global-requirements.txt#L210
If you rebase to a version > 4.0.2, you *must* also merge this patch:
https://github.com/rohe/pysaml2/pull/385
---
Note that the proposed patch req
http://www.debian.org/security/2017/dsa-3759http://www.openwall.com/lists/oss-security/2017/01/19/5http://www.securityfocus.com/bid/97692https://access.redhat.com/errata/RHSA-2017:0936https://access.redhat.com/errata/RHSA-2017:0937https://access.redhat.com/errata/RHSA-2017:0938https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850716https://github.com/rohe/pysaml2/commit/6e09a25d9b4b7aa7a506853210a9a14100b8bc9bhttps://github.com/rohe/pysaml2/issues/366https://github.com/rohe/pysaml2/pull/379http://www.debian.org/security/2017/dsa-3759http://www.openwall.com/lists/oss-security/2017/01/19/5http://www.securityfocus.com/bid/97692https://access.redhat.com/errata/RHSA-2017:0936https://access.redhat.com/errata/RHSA-2017:0937https://access.redhat.com/errata/RHSA-2017:0938https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850716https://github.com/rohe/pysaml2/commit/6e09a25d9b4b7aa7a506853210a9a14100b8bc9bhttps://github.com/rohe/pysaml2/issues/366https://github.com/rohe/pysaml2/pull/379
2017-03-24
Published