CVE-2013-1336: Input Validation
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-1336?
CVE-2013-1336 has a severity rating of important, indicating a significant risk that could lead to exploitation.
How do I fix CVE-2013-1336?
To fix CVE-2013-1336, you should apply the latest security updates provided by Microsoft for the affected .NET Framework versions.
What versions of .NET Framework are affected by CVE-2013-1336?
CVE-2013-1336 affects Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.0, and 4.5.
What type of attack does CVE-2013-1336 enable?
CVE-2013-1336 enables remote attackers to undetected changes to signed XML documents while preserving signature validity.
Is CVE-2013-1336 related to signature verification?
Yes, CVE-2013-1336 involves improper signature verification in the Common Language Runtime of the .NET Framework.