CVE-2013-2153

Severity

43%

Complexity

86%

Confidentiality

48%

The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to reuse signatures and spoof arbitrary content via crafted Reference elements in the Signature, aka "XML Signature Bypass issue."

The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 allows context-dependent attackers to reuse signatures and spoof arbitrary content via crafted Reference elements in the Signature, aka "XML Signature Bypass issue."

CVSS 2.0 Base Score 4.3. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).

Overview

Type

Apache Software Foundation XML Security for C++

First reported 11 years ago

2013-08-20 22:55:00

Last updated 6 years ago

2018-11-08 11:29:00

Affected Software

Apache Software Foundation XML Security for C++ 0.1.0

0.1.0

Apache Software Foundation XML Security for C++ 0.2.0

0.2.0

Apache Software Foundation XML Security for C++ 1.1.0

1.1.0

Apache Software Foundation XML Security for C++ 1.2.0

1.2.0

Apache Software Foundation XML Security for C++ 1.2.1

1.2.1

Apache Software Foundation XML Security for C++ 1.3.0

1.3.0

Apache Software Foundation XML Security for C++ 1.3.1

1.3.1

Apache Software Foundation XML Security for C++ 1.4.0

1.4.0

Apache Software Foundation XML Security for C++ 1.5.0

1.5.0

Apache Software Foundation XML Security for C++ 1.5.1

1.5.1

Apache Software Foundation XML Security for C++ 1.6.0

1.6.0

Apache Software Foundation XML Security for C++ 1.6.1

1.6.1

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.