Advisories ยป MGASA-2014-0552

Updated wss4j packages fix CVE-2014-3623

Publication date: 26 Dec 2014
Modification date: 26 Dec 2014
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-3623

Description

Updated wss4j packages fixes security vulnerability:

Apache WSS4J before 1.6.17, when using TransportBinding, does not properly
enforce the SAML SubjectConfirmation method security semantics, which allows
remote attackers to conduct spoofing attacks via unspecified vectors
(CVE-2014-3623).
                

References

SRPMS

4/core