CVE-2018-0486
Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct…
Does this matter?
Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.
Description
Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 1.53% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-347
- Affected
- shibboleth/xmltooling-c · debian/debian linux
- Source
- security@debian.org
References
- http://www.securitytracker.com/id/1040177Third Party Advisory, VDB Entry
- https://lists.debian.org/debian-lts-announce/2018/01/msg00016.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-security-announce/2018/msg00007.htmlMailing List, Third Party Advisory
- https://shibboleth.net/community/advisories/secadv_20180112.txtVendor Advisory
- https://www.debian.org/security/2018/dsa-4085Third Party Advisory
- http://www.securitytracker.com/id/1040177Third Party Advisory, VDB Entry
- https://lists.debian.org/debian-lts-announce/2018/01/msg00016.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-security-announce/2018/msg00007.htmlMailing List, Third Party Advisory
- https://shibboleth.net/community/advisories/secadv_20180112.txtVendor Advisory
- https://www.debian.org/security/2018/dsa-4085Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.