CVE Vulnerabilities

CVE-2019-9628

Improper Handling of Exceptional Conditions

Published: Apr 11, 2019 | Modified: Apr 18, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Xmltooling Xmltooling_project * 3.0.4 (excluding)
Xmltooling Ubuntu bionic *
Xmltooling Ubuntu cosmic *
Xmltooling Ubuntu devel *
Xmltooling Ubuntu trusty *
Xmltooling Ubuntu upstream *
Xmltooling Ubuntu xenial *

References