First published: Wed Apr 12 2017(Updated: )
The defusedxml package contains several Python-only updates for security vulnerabilities in Python's XML libraries. Defusedxml functions and classes can be used instead of the originals to protect against entity-expansion and DTD-retrieval issues.<br>PySAML2 is the python implementation of SAML Version 2, containing all the functionality for building a SAML2 service provider or an identity provider, to be used in a WSGI environment.<br>Security Fix(es):<br><li> An XML entity expansion vulnerability was found in python-pysaml2. A remote attacker could send a crafted request which would cause denial of service through resource exhaustion. (CVE-2016-10149)</li>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/python-defusedxml | <0.5.0-1.el7 | 0.5.0-1.el7 |
redhat/python-pysaml2 | <3.0.2-3.el7 | 3.0.2-3.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.