Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.66051
Kategorie:Debian Local Security Checks
Titel:Debian Security Advisory DSA 1895-2 (opensaml2, shibboleth-sp2)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to opensaml2, shibboleth-sp2
announced via advisory DSA 1895-2.

In DSA-1895-1, the xmltooling package was updated to address several
security issues. It turns out that the change related to SAML
metadata processing for key constraints caused problems when applied
without the matching changes in the opensaml2 and shibboleth-sp2
packages.

For the stable distribution (lenny), this problem has been fixed in
version 2.0-2+lenny1 of the opensaml2 packages, and version
2.0.dfsg1-4+lenny1 of the shibboleth-sp2 packages.

We recommend that you upgrade your opensaml2 and shibboleth-sp2

Solution:
http://www.securityspace.com/smysecure/catid.html?in=DSA%201895-2

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-3474
BugTraq ID: 36516
http://www.securityfocus.com/bid/36516
Debian Security Information: DSA-1895 (Google Search)
http://www.debian.org/security/2009/dsa-1895
Debian Security Information: DSA-1896 (Google Search)
http://www.debian.org/security/2009/dsa-1896
http://secunia.com/advisories/36855
http://secunia.com/advisories/36868
http://secunia.com/advisories/36876
XForce ISS Database: opensaml-keydescriptor-security-bypass(53474)
https://exchange.xforce.ibmcloud.com/vulnerabilities/53474
Common Vulnerability Exposure (CVE) ID: CVE-2009-3475
http://secunia.com/advisories/36861
CopyrightCopyright (c) 2009 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.