Updated wss4j packages fix CVE-2014-3623
Publication date: 26 Dec 2014Modification date: 26 Dec 2014
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-3623
Description
Updated wss4j packages fixes security vulnerability: Apache WSS4J before 1.6.17, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors (CVE-2014-3623).
References
SRPMS
4/core
- wss4j-1.6.17-1.mga4