[Full-disclosure] CVE-2013-2210

2013-06-27 Thread Cantor, Scott
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 CVE-2013-2210: Apache Santuario XML Security for C++ contains a heap overflow during XPointer evaluation Severity: Critical Vendor: The Apache Software Foundation Versions Affected: Apache Santuario XML Security for C++ library versions prior to

[Full-disclosure] CVE-2013-2153: Apache Santuario C++ signature bypass vulnerability

2013-06-18 Thread Cantor, Scott
CVE-2013-2153: Apache Santuario XML Security for C++ contains an XML Signature Bypass issue Severity: Critical Vendor: The Apache Software Foundation Versions Affected: Apache Santuario XML Security for C++ library versions prior to V1.7.1 Description: The implementation of XML digital

[Full-disclosure] CVE-2013-2154: Apache Santuario C++ stack overflow vulnerability

2013-06-18 Thread Cantor, Scott
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 CVE-2013-2154: Apache Santuario XML Security for C++ contains a stack overflow during XPointer evaluation Severity: Critical Vendor: The Apache Software Foundation Versions Affected: Apache Santuario XML Security for C++ library versions prior to

[Full-disclosure] CVE-2013-2155: Apache Santuario C++ denial of service vulnerability

2013-06-18 Thread Cantor, Scott
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 CVE-2013-2155: Apache Santuario XML Security for C++ contains denial of service and hash length bypass issues while processing HMAC signatures Severity: Critical Vendor: The Apache Software Foundation Versions Affected: Apache Santuario XML

Re: [Full-disclosure] CVE-2013-2156: Apache Santuario C++ heap overflow vulnerability

2013-06-18 Thread Cantor, Scott
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 CVE-2013-2156: Apache Santuario XML Security for C++ contains heap overflow while processing InclusiveNamespace PrefixList Severity: Critical Vendor: The Apache Software Foundation Versions Affected: Apache Santuario XML Security for C++ library

[Full-disclosure] Security Advisory: CVE-2011-2516

2011-07-07 Thread Cantor, Scott E.
Please be advised that a security issue affecting the Apache XML Security Library for C++ has been identified and an updated version released to address the issue. The full text of the advisory is below, and a signed version can be found at: http://santuario.apache.org/secadv/CVE-2011-2516.txt