CVE-2016-10149: XEE

Published Oct 31, 2016
·
Updated

An entity expansion vulnerability was found in python-pysaml2.

Upstream patch:

https://github.com/rohe/pysaml2/commit/6e09a25d9b4b7aa7a506853210a9a14100b8bc9b

References:

http://seclists.org/oss-sec/2017/q1/140

Other sources

An XML entity expansion vulnerability was found in python-pysaml2. A remote attacker could send a crafted request which would cause denial of service through resource exhaustion.

XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.

Affected Software

6 affected componentsFixes available
redhat/python-defusedxml<0:0.5.0-1.el7
0:0.5.0-1.el7
redhat/python-pysaml2<0:3.0.2-3.el7
0:3.0.2-3.el7
pip/pysaml2<=4.4.0
4.5.0
debian/python-pysaml2
6.5.1-17.0.1-27.5.0-2
Pysaml2 Project Pysaml2<=4.4.0
Debian Debian Linux=8.0

Event History

Oct 31, 2016
CVE Published
12:00 AM
Jan 9, 2017
Data Sourced
via Debian·03:30 PM
SeverityAffected Software
Jan 23, 2017
Data Sourced
via Red Hat·01:51 PM
DescriptionSeverityAffected Software
Mar 24, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Jul 16, 2018
Advisory Published
via GitHub·04:50 PM

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2016-10149?

CVE-2016-10149 is classified as a moderate severity vulnerability.

2

What software is affected by CVE-2016-10149?

CVE-2016-10149 affects python-pysaml2 versions up to 0:3.0.2-3.el7 and python-defusedxml versions up to 0:0.5.0-1.el7.

3

How do I fix CVE-2016-10149?

To resolve CVE-2016-10149, upgrade to python-pysaml2 version 4.5.0 or higher and python-defusedxml version 0:0.5.0-1.el7 or higher.

4

What type of vulnerability is CVE-2016-10149?

CVE-2016-10149 is an entity expansion vulnerability.

5

Does CVE-2016-10149 affect Debian systems?

Yes, CVE-2016-10149 affects Debian systems with python-pysaml2 versions before 6.5.1-1, 7.0.1-2, or 7.5.0-2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203