Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.65003
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 1896-1 (opensaml, shibboleth-sp)
Summary:NOSUMMARY
Description:Description:
The remote host is missing an update to opensaml, shibboleth-sp
announced via advisory DSA 1896-1.

Several vulnerabilities have been discovered in the opensaml and
shibboleth-sp packages, as used by Shibboleth 1.x:

Chris Ries discovered that decoding a crafted URL leads to a crash
(and potentially, arbitrary code execution).

Ian Young discovered that embedded NUL characters in certificate names
were not correctly handled, exposing configurations using PKIX trust
validation to impersonation attacks.

Incorrect processing of SAML metadata ignored key usage constraints.

For the old stable distribution (etch), these problems have been fixed
in version 1.3f.dfsg1-2+etch1 of the shibboleth-sp packages, and
version 1.1a-2+etch1 of the opensaml packages.

For the stable distribution (lenny), these problems have been fixed in
version 1.3.1.dfsg1-3+lenny1 of the shibboleth-sp packages, and
version 1.1.1-2+lenny1 of the opensaml packages.

The unstable distribution (sid) does not contain Shibboleth 1.x
packages.

This update requires restarting the affected services (mainly Apache)
to become effective.

We recommend that you upgrade your Shibboleth 1.x packages.

Solution:
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201896-1

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-3474
BugTraq ID: 36516
http://www.securityfocus.com/bid/36516
Debian Security Information: DSA-1895 (Google Search)
http://www.debian.org/security/2009/dsa-1895
Debian Security Information: DSA-1896 (Google Search)
http://www.debian.org/security/2009/dsa-1896
http://secunia.com/advisories/36855
http://secunia.com/advisories/36868
http://secunia.com/advisories/36876
XForce ISS Database: opensaml-keydescriptor-security-bypass(53474)
https://exchange.xforce.ibmcloud.com/vulnerabilities/53474
Common Vulnerability Exposure (CVE) ID: CVE-2009-3475
http://secunia.com/advisories/36861
CopyrightCopyright (c) 2009 E-Soft Inc. http://www.securityspace.com

This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2024 E-Soft Inc. All rights reserved.