Bug 779901 (CVE-2012-4418) - VUL-0: CVE-2012-4418: axis2: XML Signature Wrapping Attack
Summary: VUL-0: CVE-2012-4418: axis2: XML Signature Wrapping Attack
Status: RESOLVED INVALID
Alias: CVE-2012-4418
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Michal Vyskocil
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-09-12 06:22 UTC by Sebastian Krahmer
Modified: 2019-06-17 09:27 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2012-09-12 06:22:14 UTC
Public, via oss-sec:


Juraj Somorovsky and colleagues have described an XML Signature Wrapping (XSW) attack against a
+variety of platforms in a paper delivered at USENIX [0]. Various platforms are covered, including
+OpenSAML and Apache Axis2. OpenSAML is covered by CVE-2011-1411 [1], but I can't find a CVE ID
+for Axis2. Could one please be assigned? The OpenSAML CVE ID is 2011 because some vendors were
+given pre-notification of the issue in 2011. Since all the details were made public in 2012, I
+suggest assigning a 2012 CVE ID for Axis2.

Thanks
--
David Jorm / Red Hat Security Response Team
 
[0] http://www.nds.rub.de/media/nds/veroeffentlichungen/2012/08/22/BreakingSAML_3.pdf
[1] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1411
Comment 1 Swamp Workflow Management 2012-09-12 22:00:14 UTC
bugbot adjusting priority
Comment 3 Michal Vyskocil 2012-09-14 11:43:53 UTC
I don't think we are affected, but I will need to look closer.
Comment 5 Matthias Weckbecker 2012-10-11 08:33:46 UTC
There has been another issue found in axis2: 

  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5351
Comment 7 Michal Vyskocil 2012-10-11 08:51:45 UTC
I would say we can reject the CVE-2012-4418 as Debian did
http://security-tracker.debian.org/tracker/CVE-2012-4418

The CVE-2012-5351 is not yet declined, but I doubt we are vulnerable as well
http://security-tracker.debian.org/tracker/CVE-2012-5351

We can wait on the rejection, or close it now ...
Comment 8 Matthias Weckbecker 2012-10-11 09:12:40 UTC
Let's close it now. Thank you for looking into it so quickly, Michal!