Vulnerability Bulletins

DSA-4085 xmltooling - security update

   
Affected software Debian
 
Philip Huppert discovered the Shibboleth service provider is vulnerableto impersonation attacks and information disclosure due to mishandlingof DTDs in the XMLTooling XML parsing library. For additional detailsplease refer to the upstream advisory athttps://shibboleth.net/community/advisories/secadv_20180112.txt

More info:

https://www.debian.org/security/2018/dsa-4085