Security Advisory

CVE-2018-0486

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-01-13 18:00:00
Last updated 2024-08-05 03:28:11
Assigner debian
State PUBLISHED

Description

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.