Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Fedora 11 XML-Security-C Critical Authentication Bypass Fix 2009-8157

fedora
Calendar Grey July 31, 2009
Scroller Fedora
Addresses significant vulnerability in xml-security-c on Fedora. Implement updates to mitigate XMLDsig impersonation risks and improve overall security.
Fixes CVE-2009-0217 (#511915)

Summary

The xml-security-c library is a C++ implementation of the XML Digital Signature

specification. The library makes use of the Apache XML project's Xerces-C XML

Parser and Xalan-C XSLT processor. The latter is used for processing XPath and

XSLT transforms.

Update Information:

Fixes CVE-2009-0217 (#511915)

Change Log

References


[ 1 ] Bug #511915 - CVE-2009-0217 xmlsec1, mono, xml-security-c, xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass https://bugzilla.redhat.com/show_bug.cgi?id=511915

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update xml-security-c' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: xml-security-c
Product: Fedora 11
Version: 1.5.1
Release: 1.fc11
URL: Summary : C++ Implementation of W3C security standards for XML

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.