CVE-2019-9628 PUBLISHED

The XMLTooling library all versions prior to V3.0.4, provided with the OpenSAML and Shibboleth Service Provider software, contains an XML parsing class. Invalid data in the XML declaration causes an exception of a type that was not handled properly in the parser class and propagates an unexpected exception type.

EPSS 0.80% · 73.9th percentile

Risk Scores

EPSS Score
0.80%
73.9th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSxmltooling1.6.3-1, 1.6.2-1, 1.6.0-5build1
Ubuntu:14.04:LTSxmltooling0, 1.5.3-2, 1.5.3-2+deb8u1build0.14.04.1
Ubuntu:16.04:LTSxmltooling1.5.6-2ubuntu0.2, 1.5.6-2ubuntu0.1, 1.5.6-2

Timeline

References

Open in Interactive Console →