Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 438
Alerts This Week
Warning Icon 1 438

Ubuntu 10.04 LTS USN-2028-1 Critical: libxml-security-java Spoofing Issue

ubuntu
Calendar Grey November 12, 2013
Scroller Ubuntu
Apache XML Security for Java can enable fraudulent signature validation. It's crucial to upgrade Ubuntu 10.04 to address this severe vulnerability.
Apache XML Security for Java could be tricked into validating spoofed signatures.

Summary

Apache XML Security for Java could be tricked into validating spoofed

signatures.

Software Description:

- libxml-security-java: implementation of security standards for XML

Details:

James Forshaw discovered that Apache XML Security for Java incorrectly

validated CanonicalizationMethod parameters. An attacker could use this

flaw to spoof XML signatures.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
  libxml-security-java            1.4.3-2ubuntu0.1

In general, a standard system update will make all the necessary changes.

References

CVE-2013-2172

Severity
critical
Lowest
Low
Medium
High
Critical

November 12, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.