Bugtraq mailing list archives
[SECURITY] [DSA 2219-1] xmlsec1 security update
From: Thijs Kinkhorst <thijs () debian org>
Date: Mon, 18 Apr 2011 23:02:30 +0200 (CEST)
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2219-1 security () debian org http://www.debian.org/security/ Thijs Kinkhorst April 18, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : xmlsec1 Vulnerability : arbitrary file overwrite Problem type : local (remote) Debian-specific: no CVE ID : CVE-2011-1425 Debian Bug : 620560 Nicolas Gregoire discovered that the XML Security Library xmlsec allowed remote attackers to create or overwrite arbitrary files through specially crafted XML files using the libxslt output extension and a ds:Transform element during signature verification. For the oldstable distribution (lenny), this problem has been fixed in version 1.2.9-5+lenny1. For the stable distribution (squeeze), this problem has been fixed in version 1.2.14-1+squeeze1. For the testing distribution (wheezy) and unstable distribution (sid), this problem has been fixed in version 1.2.14-1.1. We recommend that you upgrade your xmlsec1 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: debian-security-announce () lists debian org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQEcBAEBAgAGBQJNrKVkAAoJEOxfUAG2iX57C/8H/1YbWAVCpmuYmnS1jP+RLkT3 OTq6j7m+tVmVKnlWPn0kdCZN8rTECrXZ3cL/N9sL/x9JKWg9rUINiLc2qE6lnbZm UrKMx9DNByeTPgMk4VEQ7jSpUIuNFv0xSI7K6xcce7iLeMd/otEr8KNOcQHPUz2S nhHmQv5N9HaIhv13lIr6dwzm59Muv7QVsumSIuMS8auallPI8j6K2I7QAb3xDUIP jywE4KH3dJx8aUsGubOJcfasFsBJFfrKMi9BAUgyBdH+MwRFHu4F8Sx5QB0c2dSz 7zd57itFgCzo0JvGGO0/1oypv4uFx9cPniQmYNvomLk780W6dNLptExEL5jUmQo= =0kqB -----END PGP SIGNATURE-----
Current thread:
- [SECURITY] [DSA 2219-1] xmlsec1 security update Thijs Kinkhorst (Apr 19)