1 results (0.009 seconds)

CVSS: 5.0EPSS: 2%CPEs: 16EXPL: 1

Off-by-one error in the XML signature feature in Apache XML Security for C++ 1.6.0, as used in Shibboleth before 2.4.3 and possibly other products, allows remote attackers to cause a denial of service (crash) via a signature using a large RSA key, which triggers a buffer overflow. Error de superación de límite (off-by-one) en la característica de firma XML en Apache XML Security para C++ v1.6.0,usado en Shibboleth anterior a v2.4.3 y posiblemente otros productos, permite a atacantes remotos provocar una denegación de servicio (caída) a través de una firma utilizando una clave RSA larga, que provoca un desbordamiento de búfer. • http://lists.fedoraproject.org/pipermail/package-announce/2011-July/063159.html http://lists.fedoraproject.org/pipermail/package-announce/2011-July/063229.html http://santuario.apache.org/secadv/CVE-2011-2516.txt http://secunia.com/advisories/45151 http://secunia.com/advisories/45191 http://secunia.com/advisories/45198 http://secunia.com/advisories/45491 http://shibboleth.internet2.edu/secadv/secadv_20110706.txt http://www.debian.org/security/2011/dsa-2277 http://www.securityfocus.com/ar • CWE-189: Numeric Errors •