[ubuntu/mantic-proposed] xmltooling 3.2.4-1 (Accepted)

Simon Quigley tsimonq2 at ubuntu.com
Fri Aug 4 02:48:15 UTC 2023


xmltooling (3.2.4-1) unstable; urgency=medium

  * [f89bdd8] New upstream release: 3.2.4
    SECURITY: corrects a server-side request forgery (SSRF) vulnerability.
    From https://shibboleth.net/community/advisories/secadv_20230612.txt:
    # Parsing of KeyInfo elements can cause remote resource access
    Including certain legal but "malicious in intent" content in the
    KeyInfo element defined by the XML Signature standard will result
    in attempts by the SP's shibd process to dereference untrusted URLs.
    While the content of the URL must be supplied within the message
    and does not include any SP internal state or dynamic content,
    there is at minimum a risk of denial of service, and the attack
    could be combined with others to create more serious vulnerabilities
    in the future. (Closes: #1037948)
  * [79533dd] Delete upstreamed patch
  * [6ae406d] Remove Etienne Dysli Metref from Uploaders.
    Thanks for your work, Etienne, and best wishes for your future
    endeavors!

Date: 2023-06-15 04:39:46.700321+00:00
Signed-By: Simon Quigley <tsimonq2 at ubuntu.com>
https://launchpad.net/ubuntu/+source/xmltooling/3.2.4-1
-------------- next part --------------
Sorry, changesfile not available.


More information about the mantic-changes mailing list