CVE-2013-2172
libxml-security-java - security update
EPSS 5.9%
描述
jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."
如何修補 CVE-2013-2172
要修補 CVE-2013-2172,請將受影響套件升級到下列已修補版本。
- Debian/libxml-security-java—升級至 1.5.5-2 或更新版本
- Debian/libxml-security-java—升級至 1.4.3-2+deb6u1 或更新版本
- —升級至 1.4.5-1+deb7u1 或更新版本
- —升級至 1.4.8 或更新版本
CVE-2013-2172 正在被利用嗎?
中等 — EPSS 為 5.9%,可持續追蹤但非最高優先。
受影響套件(4)
- from 0, < 1.5.5-2
- from 0, < 1.4.3-2+deb6u1
- from 0, < 1.4.5-1+deb7u1
- >= 1.4.0, < 1.4.8