logo

Database

Improper resource allocation In org.apache.santuario:xmlsec

Description

Inefficient Algorithmic Complexity in Apache Santuario XML Security jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 and 1.5.x before 1.5.5 allows context-dependent attackers to spoof an XML Signature by using the CanonicalizationMethod parameter to specify an arbitrary weak "canonicalization algorithm to apply to the SignedInfo part of the Signature."

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions

References

1. https://github.com/apache/santuario-java/commit/25e0e11493b061749f778030036cb5c406b345902. https://github.com/apache/santuario-java/commit/8e8f8bf92a43608d7d5f9e357fae19244454a61f3. https://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3%40%3Ccommits.santuario.apache.org%3E4. https://lists.apache.org/thread.html/680e6938b6412e26d5446054fd31de2011d33af11786b989127d1cc3@%3Ccommits.santuario.apache.org%3E5. https://lists.apache.org/thread.html/r1c07a561426ec5579073046ad7f4207cdcef452bb3100abaf908e0cd%40%3Ccommits.santuario.apache.org%3E6. https://lists.apache.org/thread.html/r1c07a561426ec5579073046ad7f4207cdcef452bb3100abaf908e0cd@%3Ccommits.santuario.apache.org%3E7. https://web.archive.org/web/20160317145515/http://www.securityfocus.com/archive/1/534161/100/0/threaded8. https://web.archive.org/web/20200228060314/http://www.securityfocus.com/bid/608469. http://rhn.redhat.com/errata/RHSA-2013-1207.html10. http://rhn.redhat.com/errata/RHSA-2013-1208.html11. http://rhn.redhat.com/errata/RHSA-2013-1209.html12. http://rhn.redhat.com/errata/RHSA-2013-1217.html13. http://rhn.redhat.com/errata/RHSA-2013-1218.html14. http://rhn.redhat.com/errata/RHSA-2013-1219.html15. http://rhn.redhat.com/errata/RHSA-2013-1220.html16. http://rhn.redhat.com/errata/RHSA-2013-1375.html17. http://rhn.redhat.com/errata/RHSA-2013-1437.html18. http://rhn.redhat.com/errata/RHSA-2013-1853.html19. http://rhn.redhat.com/errata/RHSA-2014-0212.html20. http://santuario.apache.org/secadv.data/CVE-2013-2172.txt.asc21. http://seclists.org/fulldisclosure/2014/Dec/2322. http://svn.apache.org/viewvc/santuario/xml-security-java/branches/1.5.x-fixes/src/main/java/org/apache/jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java?r1=1353876&r2=1493772&pathrev=1493772&diff_format=h23. http://www.debian.org/security/2014/dsa-306524. http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html25. http://www.ubuntu.com/usn/USN-2028-126. http://www.vmware.com/security/advisories/VMSA-2014-0012.html27. https://github.com/dawetmaster/CVE-2013-2172-santuario-java-vulnerable