DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
...
An XML Encryption backwards compatibility attack on Apache CXF is described by
CVE-2012-5575:
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5575![]()
This attack relates to a previous security advisory CVE-2011-1096
(http://cxf.apache.org/note-on-cve-2011-1096.html
). CVE-2011-1096 exploited a
cryptographic weakness in the CBC mode of XML Encryption, to conduct chosen
ciphertext attacks leading to the recovery of the entire plaintext. The fix
for CVE-2011-1096 was to switch to use GCM instead of CBC. Please see the note
linked above for more information.
...