Moderate: python-defusedxml and python-pysaml2 security update

Related Vulnerabilities: CVE-2016-10149   CVE-2016-10149  

Synopsis

Moderate: python-defusedxml and python-pysaml2 security update

Type/Severity

Security Advisory: Moderate

Topic

An update for python-defusedxml and python-pysaml2 is now available for Red Hat OpenStack Platform 9.0 (Mitaka).

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The defusedxml package contains several Python-only updates for security vulnerabilities in Python's XML libraries. Defusedxml functions and classes can be used instead of the originals to protect against entity-expansion and DTD-retrieval issues.

PySAML2 is the python implementation of SAML Version 2, containing all the functionality for building a SAML2 service provider or an identity provider, to be used in a WSGI environment.

Security Fix(es):

  • An XML entity expansion vulnerability was found in python-pysaml2. A remote attacker could send a crafted request which would cause denial of service through resource exhaustion. (CVE-2016-10149)

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenStack 9 x86_64

Fixes

  • BZ - 1415710 - CVE-2016-10149 python-pysaml2: Entity expansion issue

CVEs

References