CVE-2016-10149: XEE
An entity expansion vulnerability was found in python-pysaml2.
Upstream patch:
https://github.com/rohe/pysaml2/commit/6e09a25d9b4b7aa7a506853210a9a14100b8bc9b
References:
http://seclists.org/oss-sec/2017/q1/140
Other sources
An XML entity expansion vulnerability was found in python-pysaml2. A remote attacker could send a crafted request which would cause denial of service through resource exhaustion.
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2016-10149?
CVE-2016-10149 is classified as a moderate severity vulnerability.
What software is affected by CVE-2016-10149?
CVE-2016-10149 affects python-pysaml2 versions up to 0:3.0.2-3.el7 and python-defusedxml versions up to 0:0.5.0-1.el7.
How do I fix CVE-2016-10149?
To resolve CVE-2016-10149, upgrade to python-pysaml2 version 4.5.0 or higher and python-defusedxml version 0:0.5.0-1.el7 or higher.
What type of vulnerability is CVE-2016-10149?
CVE-2016-10149 is an entity expansion vulnerability.
Does CVE-2016-10149 affect Debian systems?
Yes, CVE-2016-10149 affects Debian systems with python-pysaml2 versions before 6.5.1-1, 7.0.1-2, or 7.5.0-2.