Oval Definition:
oval:org.mitre.oval:def:7213
Revision Date
:
2014-06-23
Version
:
20
Title
:
DSA-1947 shibboleth-sp, shibboleth-sp2, opensaml2 -- missing input sanitising
Description
:
Matt Elder discovered that Shibboleth, a federated web single sign-on system is vulnerable to script injection through redirection URLs
Family
:
unix
Class
:
patch
Status
:
ACCEPTED
Reference(s)
:
CVE-2009-3300
DSA-1947
Platform(s)
:
Debian GNU/Linux 4.0
Debian GNU/Linux 5.0
Product(s)
:
opensaml2
shibboleth-sp
shibboleth-sp2
Definition Synopsis
Release section
Debian GNU/Linux 5.0 is installed
AND
Architecture section
Architecture independent section
Installed architecture is all
AND
Packages section
libshibsp-doc is earlier than 2.0.dfsg1-4+lenny2
OR
libsaml2-doc is earlier than 2.0-2+lenny2
OR
shibboleth-sp2-schemas is earlier than 2.0.dfsg1-4+lenny2
OR
opensaml2-schemas is earlier than 2.0-2+lenny2
OR
libshib6 is earlier than 1.3.1.dfsg1-3+lenny2
OR
libsaml2-dev is earlier than 2.0-2+lenny2
OR
libshib-dev is earlier than 1.3.1.dfsg1-3+lenny2
OR
libshibsp1 is earlier than 2.0.dfsg1-4+lenny2
OR
libapache2-mod-shib2 is earlier than 2.0.dfsg1-4+lenny2
OR
libsaml2 is earlier than 2.0-2+lenny2
OR
libapache2-mod-shib is earlier than 1.3.1.dfsg1-3+lenny2
OR
opensaml2-tools is earlier than 2.0-2+lenny2
OR
libshibsp-dev is earlier than 2.0.dfsg1-4+lenny2
OR
libshib-target5 is earlier than 1.3.1.dfsg1-3+lenny2
OR
Architecture dependent section
Installed architecture is alpha
AND
Packages section
libshib6 is earlier than 1.3.1.dfsg1-3+lenny2
OR
libshib-dev is earlier than 1.3.1.dfsg1-3+lenny2
OR
libshibsp1 is earlier than 2.0.dfsg1-4+lenny2
OR
libapache2-mod-shib2 is earlier than 2.0.dfsg1-4+lenny2
OR
libapache2-mod-shib is earlier than 1.3.1.dfsg1-3+lenny2
OR
libshibsp-dev is earlier than 2.0.dfsg1-4+lenny2
OR
libshib-target5 is earlier than 1.3.1.dfsg1-3+lenny2
OR
Supported platform section
Installed architecture is powerpc
AND
Packages section
libshib6 is earlier than 1.3.1.dfsg1-3+lenny2
OR
libshib-dev is earlier than 1.3.1.dfsg1-3+lenny2
OR
libshib-target5 is earlier than 1.3.1.dfsg1-3+lenny2
OR
libapache2-mod-shib is earlier than 1.3.1.dfsg1-3+lenny2
OR
Release section
Debian GNU/Linux 4.0 is installed.
AND
Supported architectures section
Installed architecture is s390
OR
Installed architecture is amd64
OR
Installed architecture is sparc
OR
Installed architecture is arm
OR
Installed architecture is i386
OR
Installed architecture is ia64
OR
Installed architecture is alpha
OR
Installed architecture is mipsel
OR
Installed architecture is hppa
AND
Packages section
libshib6 is earlier than 1.3f.dfsg1-2+etch2
OR
libshib-dev is earlier than 1.3f.dfsg1-2+etch2
OR
libshib-target5 is earlier than 1.3f.dfsg1-2+etch2
OR
libapache2-mod-shib is earlier than 1.3f.dfsg1-2+etch2
BACK