Oval Definition:oval:com.redhat.rhsa:def:20162809
Revision Date:2016-11-21Version:635
Title:RHSA-2016:2809: ipsilon security update (Important)
Description:The ipsilon packages provide the Ipsilon identity provider service for federated single sign-on (SSO). Ipsilon links authentication providers and applications or utilities to allow for SSO. It includes a server and utilities to configure Apache-based service providers.

Security Fix(es):

  • A vulnerability was found in ipsilon in the SAML2 provider's handling of sessions. An attacker able to hit the logout URL could determine what service providers other users are logged in to and terminate their sessions. (CVE-2016-8638)

    This issue was discovered by Patrick Uiterwijk (Red Hat) and Howard Johnson.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2016-8638
    RHSA-2016:2809
    RHSA-2016:2809-00
    RHSA-2016:2809-01
    RHSA-2016:2809-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • ipsilon is earlier than 0:1.0.0-13.el7_3
  • AND ipsilon is signed with Red Hat redhatrelease2 key
  • ipsilon-authform is earlier than 0:1.0.0-13.el7_3
  • AND ipsilon-authform is signed with Red Hat redhatrelease2 key
  • ipsilon-authgssapi is earlier than 0:1.0.0-13.el7_3
  • AND ipsilon-authgssapi is signed with Red Hat redhatrelease2 key
  • ipsilon-authldap is earlier than 0:1.0.0-13.el7_3
  • AND ipsilon-authldap is signed with Red Hat redhatrelease2 key
  • ipsilon-base is earlier than 0:1.0.0-13.el7_3
  • AND ipsilon-base is signed with Red Hat redhatrelease2 key
  • ipsilon-client is earlier than 0:1.0.0-13.el7_3
  • AND ipsilon-client is signed with Red Hat redhatrelease2 key
  • ipsilon-filesystem is earlier than 0:1.0.0-13.el7_3
  • AND ipsilon-filesystem is signed with Red Hat redhatrelease2 key
  • ipsilon-infosssd is earlier than 0:1.0.0-13.el7_3
  • AND ipsilon-infosssd is signed with Red Hat redhatrelease2 key
  • ipsilon-persona is earlier than 0:1.0.0-13.el7_3
  • AND ipsilon-persona is signed with Red Hat redhatrelease2 key
  • ipsilon-saml2 is earlier than 0:1.0.0-13.el7_3
  • AND ipsilon-saml2 is signed with Red Hat redhatrelease2 key
  • ipsilon-saml2-base is earlier than 0:1.0.0-13.el7_3
  • AND ipsilon-saml2-base is signed with Red Hat redhatrelease2 key
  • ipsilon-tools-ipa is earlier than 0:1.0.0-13.el7_3
  • AND ipsilon-tools-ipa is signed with Red Hat redhatrelease2 key
  • BACK