-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 CVE-2013-2210: Apache Santuario XML Security for C++ contains a heap overflow during XPointer evaluation Severity: Critical Vendor: The Apache Software Foundation Versions Affected: Apache Santuario XML Security for C++ library versions prior to V1.7.2 Description: The attempted fix to address CVE-2013-2154 introduced the possibility of a heap overflow, possibly leading to arbitrary code execution, in the processing of malformed XPointer expressions in the XML Signature Reference processing code. An attacker could use this to exploit an application performing signature verification if the application does not block the evaluation of such references prior to performing the verification step. The exploit would occur prior to the actual verification of the signature, so does not require authenticated content. Mitigation: Applications that do not otherwise prevent the evaluation of XPointer expressions during signature verification and are using library versions older than V1.7.2 should upgrade as soon as possible. Distributors of older versions should apply the patches from this subversion revision: http://svn.apache.org/viewvc?view=revision&revision=r1496703 Credit: This issue was reported by Jon Erickson of iSIGHT Partners Labs References: http://santuario.apache.org/ http://santuario.apache.org/secadv.data/CVE-2013-2154.txt -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.13 (Darwin) iQIcBAEBCgAGBQJRy4zwAAoJEDeLhFQCJ3lin88QALve0Q1GXUQMQsJeqpS2IKI0 FUHhlVhOBVUOjhT3Q1+TfXHqTubJ6Rb6sAhPHB1YzKkeJwyWcRVKi4/1AVGcp3Nq e1fBNz3zrLQpYyjkmoPxUv/SADRtn8mbED1/WAJ2K3iQJ951FWkDpC8MTJhlJBEJ FUh6hXMZJpiA4KGidsAJDpvsqZhOAUKDwxD7s0rdmadc+/dB2PigDXcJxgdG9Dz3 eQYS+UkvhUCAIU8TxJaCqEECGYAe015AikbroMHUdhmNsP4otke2HOBz1xcs8YCb KyNlm0HmQ7S4Qv0UEeAyCzHXITAw7lRD5tp7/y9ZcHbLPZHAgMtFmcup5O7/xrVb h9Mh+uZ1C2atEPd/ME3/JqNDSAzxcT+Wa3SEQrnQXUVfpomE3Pztg3EUYPL8x/ln WO+pobIyTMPTEQ1rTI3LPliG8JDU4QS1HY+VQzlspNsVF2buDrOprgKAYx3MWnz3 /YvThnNNumXx7EjX/KN5RVmLavWSfJSGk725dYcaePAtLNIBHIWbkvZitsJSlrg7 0mTj8eAza79/UYWaWyz0zzd1y5bYq0m582hwSI9r45hdB32agvi5IqkAxhswBHTk B2xga2QZynAmJGHBmvPXq8fmwFw7VOZ6H+M55fNCHnb4XA96OZGb5+aZCRX2m5+X Gf+o5DTdMpinSzoT2ax2 =hZu/ -----END PGP SIGNATURE-----