CVE-2018-0486Improper Verification of Cryptographic Signature in Xmltooling-c

Severity
6.5MEDIUMNVD
EPSS
0.8%
top 26.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateMay 14

Description

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages3 packages

Debianxmltooling_project/xmltooling< 1.6.4-1+7
NVDarubanetworks/clearpass6.7.06.7.2+1

Also affects: Debian Linux 7.0, 8.0, 9.0

🔴Vulnerability Details

6
GHSA
GHSA-4479-q654-wmq5: Shibboleth XMLTooling-C before 12022-05-14
GHSA
GHSA-34v3-mf7p-7v76: Shibboleth XMLTooling-C before 12022-05-14
CVEList
CVE-2018-0489: Shibboleth XMLTooling-C before 12018-02-27
OSV
CVE-2018-0489: Shibboleth XMLTooling-C before 12018-02-27
CVEList
CVE-2018-0486: Shibboleth XMLTooling-C before 12018-01-13

📋Vendor Advisories

4
Red Hat
openSAML: Mishandling of comments in SAML content can lead to bypass of signature verification2018-02-27
Red Hat
xmltooling: impersonation attack and sensitive information disclosure in the Service Provider via crafted DTD2018-01-12
Debian
CVE-2018-0486: xmltooling - Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider bef...2018
Debian
CVE-2018-0489: xmltooling - Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider bef...2018

💬Community

2
Bugzilla
CVE-2018-0486 xmltooling: impersonation attack and sensitive information disclosure in the Service Provider via crafted DTD [fedora-all]2018-01-15
Bugzilla
CVE-2018-0486 xmltooling: impersonation attack and sensitive information disclosure in the Service Provider via crafted DTD2018-01-15
CVE-2018-0486 — Shibboleth Xmltooling-c vulnerability | cvebase