USN-6274-1: XMLTooling vulnerability
Published Aug 3, 2023
·Updated
Jurien de Jong discovered that XMLTooling did not properly handle certain KeyInfo element content within an XML signature. An attacker could possibly use this issue to achieve server-side request forgery.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/libxmltooling6v5<1.5.6-2ubuntu0.3+esm1
1.5.6-2ubuntu0.3+esm1
Ubuntu Ubuntu=16.04
Event History
Aug 3, 2023
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID of this advisory?
The vulnerability ID of this advisory is USN-6274-1.
2
What is the title of this advisory?
The title of this advisory is USN-6274-1: XMLTooling vulnerability.
3
Who discovered the vulnerability?
Jurien de Jong discovered the vulnerability.
4
What is the impact of the vulnerability?
The vulnerability could allow an attacker to achieve server-side request forgery.
5
How can I fix this vulnerability?
To fix this vulnerability, update libxmltooling6v5 package to version 1.5.6-2ubuntu0.3+esm1 or later.