Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Debian: DSA-2284-1 Critical: OpenSAML2 XML Signature Attack

debian
Calendar Grey July 25, 2011
Debian Logo
Explore the latest Debian security patch that tackles the vulnerabilities caused by XML signature wrapping in OpenSAML2, to guarantee the safety of your infrastructure.
Juraj Somorovsky, Andreas Mayer, Meiko Jensen, Florian Kohlar, Marco Kampmann and Joerg Schwenk discovered that Shibboleth, a federated web single sign-on system is vulnerable to X...

Summary

Juraj Somorovsky, Andreas Mayer, Meiko Jensen, Florian Kohlar, Marco
Kampmann and Joerg Schwenk discovered that Shibboleth, a federated web
single sign-on system is vulnerable to XML signature wrapping attacks.
More details can be found in the Shibboleth
advisory at

For the oldstable distribution (lenny), this problem has been fixed in
version 2.0-2+lenny3.

For the stable distribution (squeeze), this problem has been fixed in
version 2.3-2+squeeze1.

For the unstable distribution (sid), this problem will be fixed soon.

We recommend that you upgrade your opensaml2 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: opensaml2
CVE ID: CVE-2011-1411

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here