Debian Xml-Security-C vulnerabilities
7 known vulnerabilities affecting debian/xml-security-c.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM3LOW1
Vulnerabilities
Page 1 of 1
CVE-2013-2156P3HIGHCVSS 7.5fixed in xml-security-c 1.6.1-6 (bookworm)2013
CVE-2013-2156 [HIGH] CVE-2013-2156: xml-security-c - Heap-based buffer overflow in the Exclusive Canonicalization functionality (xsec...
Heap-based buffer overflow in the Exclusive Canonicalization functionality (xsec/canon/XSECC14n20010315.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PrefixList attribute.
Scope: local
bookworm: resolved (fixed in 1.6.
debian
CVE-2013-2154P3HIGHCVSS 7.5fixed in xml-security-c 1.6.1-6 (bookworm)2013
CVE-2013-2154 [HIGH] CVE-2013-2154: xml-security-c - Stack-based buffer overflow in the XML Signature Reference functionality (xsec/d...
Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions, probably related to the DSIGReference::ge
debian
CVE-2013-2210P3HIGHCVSS 7.5fixed in xml-security-c 1.6.1-7 (bookworm)2013
CVE-2013-2210 [HIGH] CVE-2013-2210: xml-security-c - Heap-based buffer overflow in the XML Signature Reference functionality in Apach...
Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions. NOTE: this is due to an incorrect fix for CVE-2013-2154.
Scope: local
bo
debian
CVE-2009-0217P3MEDIUMCVSS 5.0fixed in mono 2.4.2.3+dfsg-1 (bookworm)2009
CVE-2009-0217 [MEDIUM] CVE-2009-0217: mono - The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendati...
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML
debian
CVE-2013-2155P4MEDIUMCVSS 5.0fixed in xml-security-c 1.6.1-6 (bookworm)2013
CVE-2013-2155 [MEDIUM] CVE-2013-2155: xml-security-c - Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not...
Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which allows remote attackers to cause a denial of service or bypass the CVE-2009-0217 protection mechanism and spoof a signature via crafted length values to the (1) compareBase64StringToRaw, (2) DSIGAlgorithmHandlerDefault, or (3) DSIGAlgorithmH
debian
CVE-2011-2516P4LOWCVSS 5.0fixed in xml-security-c 1.6.1-1 (bookworm)2011
CVE-2011-2516 [MEDIUM] CVE-2011-2516: xml-security-c - Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6...
Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.6.1-1)
bullseye: resolved (fixed in
debian
CVE-2013-2153P4MEDIUMCVSS 4.3fixed in xml-security-c 1.6.1-6 (bookworm)2013
CVE-2013-2153 [MEDIUM] CVE-2013-2153: xml-security-c - The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache ...
The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to reuse signatures and spoof arbitrary content via crafted Reference elements in the Signature, aka "XML Signature Bypass issue."
Scope: local
bookworm: resolved (fixed in 1.6.1-6)
debian