imPC@ndo IT

Tracker / CVE-2011-2516

CVE-2011-2516

Medium 5.0

Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.

Affected products and versions

apache xml_security_for_c\+\+
shibboleth shibboleth-sp
shibboleth shibboleth-sp · … → 2.4.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References