First published: Thu Aug 03 2023(Updated: )
Jurien de Jong discovered that XMLTooling did not properly handle certain KeyInfo element content within an XML signature. An attacker could possibly use this issue to achieve server-side request forgery.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libxmltooling6v5 | <1.5.6-2ubuntu0.3+esm1 | 1.5.6-2ubuntu0.3+esm1 |
Ubuntu Linux | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this advisory is USN-6274-1.
The title of this advisory is USN-6274-1: XMLTooling vulnerability.
Jurien de Jong discovered the vulnerability.
The vulnerability could allow an attacker to achieve server-side request forgery.
To fix this vulnerability, update libxmltooling6v5 package to version 1.5.6-2ubuntu0.3+esm1 or later.