Debian DLA-1296-1 : xmltooling security update
High Nessus Plugin ID 107104
SynopsisThe remote Debian host is missing a security update.
DescriptionKelby Ludwig and Scott Cantor discovered that the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to incorrect XML parsing. For additional details please refer to the upstream advisory at https://shibboleth.net/community/advisories/secadv_20180227.txt
For Debian 7 'Wheezy', these problems have been fixed in version 1.4.2-5+deb7u3.
We recommend that you upgrade your xmltooling packages.
NOTE: Tenable Network Security has extracted the preceding description block directly from the DLA security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
SolutionUpgrade the affected packages.