Vulnerability Bulletins

DSA-4126 xmltooling - security update

   
Affected software Debian
 
Kelby Ludwig and Scott Cantor discovered that the Shibboleth serviceprovider is vulnerable to impersonation attacks and informationdisclosure due to incorrect XML parsing. For additional details pleaserefer to the upstream advisory athttps://shibboleth.net/community/advisories/secadv_20180227.txt

More info:

https://www.debian.org/security/2018/dsa-4126