USN-6274-1: XMLTooling vulnerability
3 August 2023
XMLTooling could be made to allow for unintended server side actions if it received specially crafted input.
Releases
Packages
- xmltooling - C++ XML parsing library with encryption support
Details
Jurien de Jong discovered that XMLTooling did not properly handle certain
KeyInfo element content within an XML signature. An attacker could possibly
use this issue to achieve server-side request forgery.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
libxmltooling6v5
-
1.5.6-2ubuntu0.3+esm1
Available with Ubuntu Pro
After a standard system update you need to restart the
shibd process to make all the necessary changes.