CVE Vulnerabilities

CVE-2015-0851

Published: Aug 12, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.

Affected Software

NameVendorStart VersionEnd Version
XmltoolingXmltooling_project*1.5.4 (including)
Opensaml2Ubuntuprecise*
Opensaml2Ubuntuupstream*
Opensaml2Ubuntuvivid*
Opensaml2Ubuntuwily*
Opensaml2Ubuntuyakkety*
XmltoolingUbuntuesm-infra-legacy/trusty*
XmltoolingUbuntuprecise*
XmltoolingUbuntutrusty*
XmltoolingUbuntutrusty/esm*
XmltoolingUbuntuupstream*
XmltoolingUbuntuvivid*
XmltoolingUbuntuwily*
XmltoolingUbuntuyakkety*

References