CVE Vulnerabilities

CVE-2015-0851

Published: Aug 12, 2015 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.

Affected Software

Name Vendor Start Version End Version
Xmltooling Xmltooling_project * 1.5.4 (including)
Opensaml2 Ubuntu precise *
Opensaml2 Ubuntu upstream *
Opensaml2 Ubuntu vivid *
Opensaml2 Ubuntu wily *
Opensaml2 Ubuntu yakkety *
Xmltooling Ubuntu precise *
Xmltooling Ubuntu trusty *
Xmltooling Ubuntu upstream *
Xmltooling Ubuntu vivid *
Xmltooling Ubuntu wily *
Xmltooling Ubuntu yakkety *

References