Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xml_security_for_c++ | Apache | 1.6.0 (including) | 1.6.0 (including) |
Shibboleth-sp | Shibboleth | * | 2.4.2 (including) |
Shibboleth-sp | Shibboleth | 1.3.1 (including) | 1.3.1 (including) |
Shibboleth-sp | Shibboleth | 1.3.2 (including) | 1.3.2 (including) |
Shibboleth-sp | Shibboleth | 1.3.3 (including) | 1.3.3 (including) |
Shibboleth-sp | Shibboleth | 1.3.4 (including) | 1.3.4 (including) |
Shibboleth-sp | Shibboleth | 1.3.5 (including) | 1.3.5 (including) |
Shibboleth-sp | Shibboleth | 1.3f (including) | 1.3f (including) |
Shibboleth-sp | Shibboleth | 2.0 (including) | 2.0 (including) |
Shibboleth-sp | Shibboleth | 2.1 (including) | 2.1 (including) |
Shibboleth-sp | Shibboleth | 2.2 (including) | 2.2 (including) |
Shibboleth-sp | Shibboleth | 2.2.1 (including) | 2.2.1 (including) |
Shibboleth-sp | Shibboleth | 2.3 (including) | 2.3 (including) |
Shibboleth-sp | Shibboleth | 2.3.1 (including) | 2.3.1 (including) |
Shibboleth-sp | Shibboleth | 2.4 (including) | 2.4 (including) |
Shibboleth-sp | Shibboleth | 2.4.1 (including) | 2.4.1 (including) |
Shibboleth-sp2 | Ubuntu | lucid | * |
Shibboleth-sp2 | Ubuntu | maverick | * |
Shibboleth-sp2 | Ubuntu | natty | * |
Shibboleth-sp2 | Ubuntu | oneiric | * |
Shibboleth-sp2 | Ubuntu | precise | * |
Shibboleth-sp2 | Ubuntu | quantal | * |
Shibboleth-sp2 | Ubuntu | raring | * |
Shibboleth-sp2 | Ubuntu | saucy | * |
Shibboleth-sp2 | Ubuntu | utopic | * |
Shibboleth-sp2 | Ubuntu | vivid | * |
Shibboleth-sp2 | Ubuntu | wily | * |
Shibboleth-sp2 | Ubuntu | yakkety | * |
Xml-security-c | Ubuntu | hardy | * |
Xml-security-c | Ubuntu | lucid | * |
Xml-security-c | Ubuntu | maverick | * |
Xml-security-c | Ubuntu | natty | * |
Xml-security-c | Ubuntu | upstream | * |