First published: Tue Sep 29 2009(Updated: )
Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before 1.2.2 as used in Internet2 Shibboleth Service Provider software 2.x before 2.2.1, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed encoded URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet2 Shibboleth-sp | =1.3.1 | |
Internet2 Shibboleth-sp | =1.3.2 | |
Internet2 Shibboleth-sp | =1.3.3 | |
Internet2 Shibboleth-sp | =1.3f | |
Internet2 Opensaml | =1.1 | |
Internet2 Opensaml | =1.1.1 | |
Internet2 Xmltooling | =1.0.1 | |
Internet2 Xmltooling | =1.1.0 | |
Internet2 Xmltooling | =1.1.1 | |
Internet2 Xmltooling | =1.2.0 | |
Internet2 Xmltooling | =1.2.1 | |
Internet2 Shibboleth-sp | =2.0 | |
Internet2 Shibboleth-sp | =2.1 | |
Internet2 Shibboleth-sp | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.