Candidate: CVE-2016-5697 PublicDate: 2017-01-23 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5697 Description: Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=828076 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_ruby-saml: upstream: https://github.com/onelogin/ruby-saml/commit/a571f52171e6bfd87db59822d1d9e8c38fb3b995 upstream_ruby-saml: needed precise_ruby-saml: DNE precise/esm_ruby-saml: DNE trusty_ruby-saml: DNE trusty/esm_ruby-saml: DNE vivid/stable-phone-overlay_ruby-saml: DNE vivid/ubuntu-core_ruby-saml: DNE wily_ruby-saml: ignored (reached end-of-life) xenial_ruby-saml: ignored (end of standard support, was needed) yakkety_ruby-saml: ignored (reached end-of-life) zesty_ruby-saml: ignored (reached end-of-life) artful_ruby-saml: ignored (reached end-of-life) bionic_ruby-saml: not-affected (1.3.0-1) cosmic_ruby-saml: not-affected (1.3.0-1) disco_ruby-saml: not-affected (1.3.0-1) eoan_ruby-saml: not-affected (1.3.0-1) focal_ruby-saml: not-affected (1.3.0-1) groovy_ruby-saml: not-affected (1.3.0-1) hirsute_ruby-saml: not-affected (1.3.0-1) impish_ruby-saml: not-affected (1.3.0-1) jammy_ruby-saml: not-affected (1.3.0-1) devel_ruby-saml: not-affected (1.3.0-1)