<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:"Times New Roman \(Body CS\)";
panose-1:2 11 6 4 2 2 2 2 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
span.EmailStyle19
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;
font-weight:normal;
font-style:normal;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;
mso-ligatures:none;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style>
</head>
<body lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">Hi Scott,<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Could you provide a link to download the latest <span style="color:#212121">
XMLTooling library for Linux?<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#212121"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="color:#212121">Thanks,<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#212121">Hong</span><o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-bottom:12.0pt"><b><span style="font-size:12.0pt;color:black">From:
</span></b><span style="font-size:12.0pt;color:black">announce <announce-bounces@shibboleth.net> on behalf of Cantor, Scott via announce <announce@shibboleth.net><br>
<b>Date: </b>Monday, June 12, 2023 at 8:35 AM<br>
<b>To: </b>announce@shibboleth.net <announce@shibboleth.net><br>
<b>Cc: </b>Cantor, Scott <cantor.2@osu.edu><br>
<b>Subject: </b>Shibboleth Service Provider Security Advisory [12 June 2023]<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal">-----BEGIN PGP SIGNED MESSAGE-----<br>
Hash: SHA512<br>
<br>
Shibboleth Service Provider Security Advisory [12 June 2023]<br>
<br>
An updated version of the XMLTooling library that is part of the<br>
OpenSAML and Shibboleth Service Provider software is now available<br>
which corrects a server-side request forgery (SSRF) vulnerability.<br>
<br>
Parsing of KeyInfo elements can cause remote resource access.<br>
=============================================================<br>
Including certain legal but "malicious in intent" content in the<br>
KeyInfo element defined by the XML Signature standard will result<br>
in attempts by the SP's shibd process to dereference untrusted<br>
URLs.<br>
<br>
While the content of the URL must be supplied within the message<br>
and does not include any SP internal state or dynamic content,<br>
there is at minimum a risk of denial of service, and the attack<br>
could be combined with others to create more serious vulnerabilities<br>
in the future.<br>
<br>
This issue is *not* specific to the V3 XMLTooling software and is<br>
believed to impact all versions prior to V3.2.4.<br>
<br>
Recommendations<br>
===============<br>
Update to V3.2.4 or later of the XMLTooling library, which is<br>
now available. Note that on Linux and similar platforms, upgrading<br>
this component will require restarting the shibd process to correct<br>
the bug.<br>
<br>
The updated version of the library has been included in a V3.4.1.3<br>
patch release of the Service Provider software on Windows.<br>
<br>
Other Notes<br>
===========<br>
The xmltooling git commit containing the fix for this issue is<br>
6080f6343f98fec085bc0fd746913ee418cc9d30 and may be in general terms<br>
applicable to V2 of the library.<br>
<br>
Credits<br>
=======<br>
Juriën de Jong, an independent security researcher in the Netherlands<br>
<br>
URL for this Security Advisory:<br>
<a href="https://shibboleth.net/community/advisories/secadv_20230612.txt">https://shibboleth.net/community/advisories/secadv_20230612.txt</a><br>
<br>
-----BEGIN PGP SIGNATURE-----<br>
<br>
iQIzBAEBCgAdFiEE3KoVAHvtneaQzZUjN4uEVAIneWIFAmSHDk4ACgkQN4uEVAIn<br>
eWKdwg/9H2DoBB5xU53ZkNPHQW2MLHvhT/EKXp+1TfL1YD6fpqBrsY1A4pJmwamA<br>
U/PRkEGV7EitP0AJZ+lWxJoMcDupu8wsPh2nm0MJUUcgkuYdD38/ixyLs1HQ4jwT<br>
SMDQsfTDlEZvbMqdr7B20HxzIGU/bX8pxgvkP1IyclfiSOBIPdbDOQG3OvdZYl5u<br>
aJv0mACkPkiH1/JbRI9ODm3zYpwe8C2vpPyBhNrOARB9QzdogN2zx7l5xDyUiHtC<br>
YJHWnSMUEn9xvZJUTS+dHZpCmh2R3cpxmbL7WsT5xHq/LH7UUXELwcOiCgUNQgDn<br>
rz5lwF2FpXKw4qQ8u49Emqjb9pqPOD+OT1gRc/j3oibqINQunmrdjWt4m8MAK6Bh<br>
eS4S3zjGw7JNfaO91PV2TYypYf6hSqGemQBlCmnVHTZqVf068S87ZpFyG1F/VRB5<br>
voEbdoOMBVGpeaan8snRoQTHEMG/tUdlmL7g076NvExH8W9dmhcWW/SiP/gWQ8ko<br>
NdUKfqYxONOBCDOlBzC9lBk6D106qbcCsnInwBHdPvWlX36M56oZU/DjV/lNMK+Y<br>
j2HS3DtBWxX+1nsrg/DLzyi+8ULOqbawyOqCaaolVjZzTOHGFwpd35XYblyb3iwb<br>
JbpmuRuk5cHGTwlHwXNI/5FzECOOe4KMLUzvrgzSiTWU89XBQ1M=<br>
=XkeU<br>
-----END PGP SIGNATURE-----<br>
<br>
--<br>
To unsubscribe from this list send an email to announce-unsubscribe@shibboleth.net<o:p></o:p></p>
</div>
</div>
</body>
</html>