<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>20785</bug_id>
          
          <creation_ts>2009-07-15 15:05:36 +0400</creation_ts>
          <short_desc>CVE-2009-0217 XML signature HMAC truncation authentication bypass</short_desc>
          <delta_ts>2011-09-10 10:52:20 +0400</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>libxmlsec1</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>WONTFIX</resolution>
          
          
          <bug_file_loc>http://www.kb.cert.org/vuls/id/466161</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>security</keywords>
          <priority>P3</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Vladimir Lettiev">crux</reporter>
          <assigned_to name="Fr. Br. George">george</assigned_to>
          <cc>andy</cc>
    
    <cc>george</cc>
    
    <cc>mike</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>94691</commentid>
    <comment_count>0</comment_count>
    <who name="Vladimir Lettiev">crux</who>
    <bug_when>2009-07-15 15:05:36 +0400</bug_when>
    <thetext>XML Signature Syntax and Processing (XMLDsig) is a W3C recommendation for providing integrity, message authentication, and/or signer authentication services for data. XMLDsig is commonly used by web services such as SOAP. The XMLDsig recommendation includes support for HMAC truncation, as specified in RFC2014. When HMAC truncation is under the control of an attacker, however, this can result in an effective authentication bypass. For example, by specifying an HMACOutputLength of 1, only one bit of the signature is verified. This can allow an attacker to forge an XML signature that will be accepted as valid.

fixed in 1.2.12</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>125115</commentid>
    <comment_count>1</comment_count>
    <who name="Michael Shigorin">mike</who>
    <bug_when>2011-09-10 10:52:20 +0400</bug_when>
    <thetext>В сизифе такого пакета уже нет; последний бранч (с 1.2.10) -- 5.0:
4.0/SRPMS/xmlsec1-1.2.10-alt1.src.rpm
4.1/SRPMS/xmlsec1-1.2.10-alt1.src.rpm
5.0/SRPMS/xmlsec1-1.2.10-alt1.1.src.rpm</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>