• [SECURITY] [DSA 4085-1] xmltooling security update

    From Moritz Muehlenhoff@1:229/2 to All on Fri Jan 12 23:20:01 2018
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4085-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff January 12, 2018 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : xmltooling
    CVE ID : CVE-2018-0486

    Philip Huppert discovered the Shibboleth service provider is vulnerable
    to impersonation attacks and information disclosure due to mishandling
    of DTDs in the XMLTooling XML parsing library. For additional details
    please refer to the upstream advisory at https://shibboleth.net/community/advisories/secadv_20180112.txt

    For the oldstable distribution (jessie), this problem has been fixed
    in version 1.5.3-2+deb8u2.

    The stable distribution (stretch) is not affected.

    We recommend that you upgrade your xmltooling packages.

    For the detailed security status of xmltooling please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/xmltooling

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlpZMmsACgkQEMKTtsN8 Tjbyvg/+JR1ZpLNDVfVSMF2Dpk8NSnLCLEXa/E0wkYoDfOJg9VU3k+USVx2I1nSB e7zUZNV5vgw7kRYXw6k8LcriE9IqO90iHWnGWa1z3J8EMFHb16hAuCBkSURalVhE rvZjFN5ehRewbblNEDd/5uP6AQ2nyYCMivu/iTf+0+gRfv0wFEEhfqQxwykVgbG0 DJrgyjtFZCwcYRDiNhZYEy9C4TcWZxKyFxPHq7L4pP6T4oBM8kQd07BhLclTEYQs aGmwxvEx2hhlYTgqQjWiDoU/FkKCLKgfSS5MqGtasNRFD4T6uRDFK2Bm2STcmNCG soi8flwr5ZKISinbAj/fz/yIYHSIO1ccV9Hp8BiiJ2uttWXGeHzNJGT9kDX2Uok4 aoxWnHC9auiw3vUR9G95fg/n7NKBtRThth9tRQb15S6RHnX8gWClu1QEm0JcxLAY Ogiy4NChOhbGJnAfClCVbkL8idi0JLAuk6UVEGFiFDwBMwWq/Dh7v5epdrLGc2et o7knduLn1QsuQWJv3U6VyCUaMD4HDOx0SzxiJ9nfesf92zIYEcFl4NuMLor5rOI7 4xo+7M3HgyWW8ycPNNhYOjX6wGUn6s91gH+aLhe/zhkGoBC5D3tAeywQrDk+bx0W E5vinxk/13F39cB3omwQb6xOFIVY0kHZAPrCO+k3E45we6f/hoU=
    =C4XH
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)