Vulnerability Description
Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via crafted XML data. NOTE: this issue exists because of an incomplete fix for CVE-2018-0486.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Shibboleth | Xmltooling-C | < 1.6.4 |
| Debian | Debian Linux | 7.0 |
| Arubanetworks | Clearpass | >= 6.6.0, <= 6.6.9 |
Related Weaknesses (CWE)
References
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-003.txtThird Party Advisory
- http://www.securityfocus.com/bid/103172Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040435Third Party AdvisoryVDB Entry
- https://lists.debian.org/debian-lts-announce/2018/02/msg00031.htmlIssue Tracking
- https://shibboleth.net/community/advisories/secadv_20180227.txtPatchVendor Advisory
- https://www.debian.org/security/2018/dsa-4126Third Party Advisory
- http://www.arubanetworks.com/assets/alert/ARUBA-PSA-2018-003.txtThird Party Advisory
- http://www.securityfocus.com/bid/103172Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040435Third Party AdvisoryVDB Entry
- https://lists.debian.org/debian-lts-announce/2018/02/msg00031.htmlIssue Tracking
- https://shibboleth.net/community/advisories/secadv_20180227.txtPatchVendor Advisory
- https://www.debian.org/security/2018/dsa-4126Third Party Advisory
FAQ
What is CVE-2018-0489?
CVE-2018-0489 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Shibboleth XMLTooling-C before 1.6.4, as used in Shibboleth Service Provider before 2.6.1.4 on Windows and other products, mishandles digital signatures of user data, which allows remote attackers to ...
How severe is CVE-2018-0489?
CVE-2018-0489 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-0489?
Check the references section above for vendor advisories and patch information. Affected products include: Shibboleth Xmltooling-C, Debian Debian Linux, Arubanetworks Clearpass.