First published: Tue Mar 31 2015(Updated: )
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet2 Shibboleth Service Provider | <=2.5.3 | |
Debian GNU/Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2684 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2015-2684, upgrade the Shibboleth Service Provider to version 2.5.4 or later.
CVE-2015-2684 affects users of Shibboleth Service Provider versions before 2.5.4 and Debian GNU/Linux 7.0.
CVE-2015-2684 is associated with a denial of service attack that can crash the Service Provider.
CVE-2015-2684 involves remote authenticated users sending crafted SAML messages that exploit the vulnerability.