Oval Definition:oval:org.mitre.oval:def:28374
Revision Date:2015-01-26Version:8
Title:RHSA-2014:1803 -- mod_auth_mellon security update (Important)
Description:mod_auth_mellon provides a SAML 2.0 authentication module for the ApacheHTTP Server.An information disclosure flaw was found in mod_auth_mellon's sessionhandling that could lead to sessions overlapping in memory. A remoteattacker could potentially use this flaw to obtain data from another user'ssession. (CVE-2014-8566)It was found that uninitialized data could be read when processing a user'slogout request. By attempting to log out, a user could possibly cause theApache HTTP Server to crash. (CVE-2014-8567)Red Hat would like to thank the mod_auth_mellon team for reporting theseissues. Upstream acknowledges Matthew Slowe as the original reporter ofCVE-2014-8566.All users of mod_auth_mellon are advised to upgrade to this updatedpackage, which contains a backported patch to correct these issues.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CESA-2014:1803
CVE-2014-8566
CVE-2014-8567
RHSA-2014:1803
Platform(s):CentOS Linux 6
Red Hat Enterprise Linux 6
Product(s):mod_auth_mellon
Definition Synopsis
  • Red Hat Enterprise Linux 6 and CentOS Linux 6 release section
  • Operation system section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • OR The operating system installed on the system is CentOS Linux 6.x
  • AND mod_auth_mellon is earlier than 0:0.8.0-3.el6_6
  • Red Hat Enterprise Linux 6 release section
  • The operating system installed on the system is Red Hat Enterprise Linux 6
  • AND mod_auth_mellon-debuginfo is earlier than 0:0.8.0-3.el6_6
  • BACK