what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Apache Santuario XML Security For C++ Denial Of Service / Bypass

Apache Santuario XML Security For C++ Denial Of Service / Bypass
Posted Jun 18, 2013
Authored by James Forshaw

A bug exists in the processing of the output length of an HMAC-based XML Signature that would cause a denial of service when processing specially chosen input. Exploitation of this issue does not require authenticated content. In very unusual cases, inputs could be chosen in such a way that the fix for the issue in CVE-2009-0217 could be bypassed, enabling improper verification of a signature. Versions prior to 1.7.1 are affected.

tags | advisory, denial of service
advisories | CVE-2013-2155
SHA-256 | 4ed699c9710bffc9e07a34e7f30bd97e55b2305af63662dc2f499d685d727662

Apache Santuario XML Security For C++ Denial Of Service / Bypass

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

CVE-2013-2155: Apache Santuario XML Security for C++ contains denial
of service and hash length bypass issues while processing HMAC signatures

Severity: Critical

Vendor: The Apache Software Foundation

Versions Affected: Apache Santuario XML Security for C++ library versions
prior to V1.7.1

Description: A bug exists in the processing of the output length of an
HMAC-based XML Signature that would cause a denial of service when
processing specially chosen input. Exploitation of this issue does
not require authenticated content.

In very unusual cases, inputs could be chosen in such a way that
the fix for the issue in CVE-2009-0217 could be bypassed, enabling
improper verification of a signature.

Mitigation: Applications that support HMAC signatures and are using library
versions older than V1.7.1 should upgrade as soon as possible. Distributors
of older versions should apply the patches from this subversion revision:

http://svn.apache.org/viewvc?view=revision&revision=1493960

Credit: This issue was reported by James Forshaw, Context Information
Security

References: http://santuario.apache.org/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.13 (Darwin)

iQIcBAEBCgAGBQJRv9gDAAoJEDeLhFQCJ3likjsP/2VC0FXAO39JWYLBPt8o48+Z
rwy0SFlqZrjcLkeC9dRvzw/EDItagyP+ir2raJhbIMzyLgHA/GSYolcrFVr5OEjK
sHXimW3c85bkjC9ygTyfXoXljwV3BNNjKvJ9ELDbt7LAVBxP/ngYIP49Ai9cGbLv
eLuvTs+GaFVUcA9w+fhyQEbIczhOhbtPM3ltugzQpLdu+xbpwkrvXL7Pge1U7KLg
9T23HpzEt/ye+RK/wih/0XntrSyHKqs1oPtyU6E8KZUFlRMFIZ541G933OVrt/HG
jdNH+0usEd3DzaCNtxf1lopLsVaPgbYcp1jOO2+JCQ97pLqtpL9qq/6asGtYViuT
lWt8hPispI6D00IDo+7iuuEokOlo3dWAJI9QZjRqYIPFE+rVHBNgUezYHv6d8Woc
Z1WWrFkCZEJhmqAylkHKHaEDPPiCINwtbzGRxFOBWuhU7Bcf1tdKDzGChyZVKz/l
A5IEQYw6pagSv8mMMhDOzKzJZSgH5mGQBmBwQ014/4/noD8zMdSsrQ/RRxmzpX9C
jIWVasOtpHQy/IJTjdjQcF4ZJvBz40i3VVQwhxHnYtl6NJXr1bGzqlC01G7nWWsG
dcBSB4MnNu+uYnev7CzlC4EZ27j2HgekmJ7GPWqKKj5R7rAFlsxjo50g1J7CUsJ3
g2CPt8V/THNSVKr26Hrz
=Z6W/
-----END PGP SIGNATURE-----

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    6 Files
  • 22
    Nov 22nd
    48 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    60 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    44 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close