4.3
CVSSv2

CVE-2013-2153

Published: 20/08/2013 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) prior to 1.7.1 allows context-dependent malicious users to reuse signatures and spoof arbitrary content via crafted Reference elements in the Signature, aka "XML Signature Bypass issue."

Vulnerable Product Search on Vulmon Subscribe to Product

apache xml security for c\\+\\+ 1.6.0

apache xml security for c\\+\\+ 1.1.0

apache xml security for c\\+\\+ 1.6.1

apache xml security for c\\+\\+ 1.2.1

apache xml security for c\\+\\+ 1.5.1

apache xml security for c\\+\\+ 1.5.0

apache xml security for c\\+\\+ 0.2.0

apache xml security for c\\+\\+ 1.3.0

apache xml security for c\\+\\+

apache xml security for c\\+\\+ 1.4.0

apache xml security for c\\+\\+ 1.3.1

apache xml security for c\\+\\+ 1.2.0

apache xml security for c\\+\\+ 0.1.0

Vendor Advisories

James Forshaw from Context Information Security discovered several vulnerabilities in xml-security-c, an implementation of the XML Digital Security specification The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-2153 The implementation of XML digital signatures in the Santuario-C++ library is vul ...