Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2014.0552
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2014-0552)
Summary:The remote host is missing an update for the 'wss4j' package(s) announced via the MGASA-2014-0552 advisory.
Description:Summary:
The remote host is missing an update for the 'wss4j' package(s) announced via the MGASA-2014-0552 advisory.

Vulnerability Insight:
Updated wss4j packages fixes security vulnerability:

Apache WSS4J before 1.6.17, when using TransportBinding, does not properly
enforce the SAML SubjectConfirmation method security semantics, which allows
remote attackers to conduct spoofing attacks via unspecified vectors
(CVE-2014-3623).

Affected Software/OS:
'wss4j' package(s) on Mageia 4.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2014-3623
BugTraq ID: 70736
http://www.securityfocus.com/bid/70736
https://lists.apache.org/thread.html/rc774278135816e7afc943dc9fc78eb0764f2c84a2b96470a0187315c@%3Ccommits.cxf.apache.org%3E
https://lists.apache.org/thread.html/r36e44ffc1a9b365327df62cdfaabe85b9a5637de102cea07d79b2dbf@%3Ccommits.cxf.apache.org%3E
https://lists.apache.org/thread.html/rff42cfa5e7d75b7c1af0e37589140a8f1999e578a75738740b244bd4@%3Ccommits.cxf.apache.org%3E
https://lists.apache.org/thread.html/rd49aabd984ed540c8ff7916d4d79405f3fa311d2fdbcf9ed307839a6@%3Ccommits.cxf.apache.org%3E
https://lists.apache.org/thread.html/rec7160382badd3ef4ad017a22f64a266c7188b9ba71394f0d321e2d4@%3Ccommits.cxf.apache.org%3E
https://lists.apache.org/thread.html/rfb87e0bf3995e7d560afeed750fac9329ff5f1ad49da365129b7f89e@%3Ccommits.cxf.apache.org%3E
http://seclists.org/oss-sec/2014/q4/437
RedHat Security Advisories: RHSA-2015:0236
http://rhn.redhat.com/errata/RHSA-2015-0236.html
RedHat Security Advisories: RHSA-2015:0675
http://rhn.redhat.com/errata/RHSA-2015-0675.html
RedHat Security Advisories: RHSA-2015:0850
http://rhn.redhat.com/errata/RHSA-2015-0850.html
RedHat Security Advisories: RHSA-2015:0851
http://rhn.redhat.com/errata/RHSA-2015-0851.html
http://secunia.com/advisories/61909
XForce ISS Database: apache-cxf-cve20143623-sec-bypass(97754)
https://exchange.xforce.ibmcloud.com/vulnerabilities/97754
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.