Mangelnde Prüfung von Signaturen in php-robrichards-xmlseclibs1
ID: | FEDORA-2020-1b95d7a131 |
Distribution: | Fedora |
Plattformen: | Fedora 30 |
Datum: | Mo, 13. April 2020, 22:49 |
Referenzen: | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3465
https://bugzilla.redhat.com/show_bug.cgi?id=1771533 |
Applikationen: | php-robrichards-xmlseclibs1 |
Originalnachricht |
|
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2020-1b95d7a131 2020-04-13 16:45:10.937085 -------------------------------------------------------------------------------- Name : php-robrichards-xmlseclibs1 Product : Fedora 30 Version : 1.4.3 Release : 1.fc30 URL : https://github.com/robrichards/xmlseclibs Summary : A PHP library for XML Security (version 1) Description : xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. NOTE: php-mcrypt will not be automatically installed as a dependency of this package so it will need to be "manually" installed if it is required -- specifically for the following XMLSecurityKey encryption types: - XMLSecurityKey::AES128_CBC - XMLSecurityKey::AES192_CBC - XMLSecurityKey::AES256_CBC - XMLSecurityKey::TRIPLEDES_CBC Autoloader: /usr/share/php/robrichards-xmlseclibs/autoload.php -------------------------------------------------------------------------------- Update Information: ## 1.4.3 (12, Nov 2019) ### Security Improvements: - Insure only a single SignedInfo element exists within a signature during verification. Refs [CVE-2019-3465](https://nvd.nist.gov/vuln/detail/CVE-2019-3465). -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 5 2020 Shawn Iwinski |