Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Apache XML Security for Java could be tricked into validating spoofed
signatures.
Software Description:
- libxml-security-java: implementation of security standards for XML
Details:
James Forshaw discovered that Apache XML Security for Java incorrectly
validated CanonicalizationMethod parameters. An attacker could use this
flaw to spoof XML signatures.
The problem can be corrected by updating your system to the following package versions: Ubuntu 10.04 LTS: libxml-security-java 1.4.3-2ubuntu0.1 In general, a standard system update will make all the necessary changes.
CVE-2013-2172
Get the latest Linux and open source security news straight to your inbox.