Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 10 Jan 2017 22:39:40 -0500
From: <cve-assign@...re.org>
To: <seb@...ian.org>
CC: <cve-assign@...re.org>, <oss-security@...ts.openwall.com>
Subject: Re: CVE request: python-pysaml2 XML external entity attack

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

> python-pysaml2 does
> not sanitize SAML XML requests or responses:
> 
>   https://github.com/rohe/pysaml2/issues/366
>   https://github.com/rohe/pysaml2/pull/379
>   https://bugs.debian.org/850716
>   https://github.com/rohe/pysaml2/commit/6e09a25d9b4b7aa7a506853210a9a14100b8bc9b

Use CVE-2016-10127 for the vulnerability addressed by "Fix XXE in XML
parsing" in 6e09a25d9b4b7aa7a506853210a9a14100b8bc9b.

The scope of this CVE does not include the various other issues that
may be found in the above references:

 - it does not include any aspect of
   https://bugzilla.gnome.org/show_bug.cgi?id=772726

 - it does not include any vulnerabilities in the XML Security Library
   (xmlsec), such as ones that are now, or previously were, listed at
   https://github.com/lsh123/xmlsec/issues

 - it does not include any CWE-776 (Entity Expansion) issues that may
   have been fixed as a side effect of
   6e09a25d9b4b7aa7a506853210a9a14100b8bc9b (possibly there are new
   test cases in 6e09a25d9b4b7aa7a506853210a9a14100b8bc9b for CWE-776)

If the references need more CVE IDs related to any of these other
topics, please let us know.

- -- 
CVE Assignment Team
M/S M300, 202 Burlington Road, Bedford, MA 01730 USA
[ A PGP key is available for encrypted communications at
  http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJYdacpAAoJEHb/MwWLVhi2dU4QAJC8fNO+tSEsFjLxhpwerqp2
dqGm/ZfdGZ717A9BROlsycopbF9nVuuTp22PMEaNgJtO+sESnVdSJomVA6XvbGsk
kd7iq+r3opeplMuyuYkuqQaw585N6MRc27WBh21Cpis8ExlU/bYH3qapTkfV1G88
h6BqmhBJ2Yzae/FfOfG/kMCbh9Nbwem7gxB1tIHmWBxvKm/TXknH/tO4hOUsZlyt
sb9SSwYLmqZHbqdv3rBvdoHHS7LwBSL0niKSCpPmyYKwI3P3lrEn+C6DmqqfZpsS
0wmMse7ILe7/u28IutqCNjA5aDzaiclEE+P7KLgl/xyyGt80icM+tzBSXXwYbzMB
YTxOiBhCiXKVlkgkNFPpq9wXBU/L5eNqsntKiuqGhFeLZIOGIpE8dSXss1ERVifG
KL1TOLCj9jPnburB0g7f6FpDB4pSiWvhL47uMdNOSDKFBCT/SP+JiqzfH0PycspT
v1OrRvQXA08xGX/2kD94os/6yrZwbFe65AdKHui/rHgbAjXLwiKSe9R86ppGJ5OV
4mAG3qgh3ZJOqX6kPPOMCM7XCxN6/KpQsnLi17Va7fIhr4nq1zAjGTPJw1PhusnZ
98NJtjIpkXLk5dCxJY3w9RWAykY26HI2k8HPsAPMPClGtJU0EeOUTkbt4Nv4Q0cF
XZiw9PXbEwe75koEvajV
=s3t6
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.