XML Digital Signature Spoofing Vulnerability (CVE-2013-1336)
Data de publicação: 21 julho 2015
Schweregrad: : Medium
Data do informe: 21 julho 2015
Descrição
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check signatures, which allows remote attackers to make undetected changes to signed XML documents via unspecified vectors that preserve signature validity, aka "XML Digital Signature Spoofing Vulnerability."
Exposição das informações
Apply associated Trend Micro DPI Rules.
Solução
Trend Micro Deep Security DPI Rule Number: 1005742