CVE-2015-2684: Input Validation
Published Mar 31, 2015
·Updated
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.
Affected Software
2 affected components
shibboleth Service Provider<=2.5.3
Debian Debian Linux=7.0
Event History
Mar 31, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2684?
CVE-2015-2684 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2015-2684?
To fix CVE-2015-2684, upgrade the Shibboleth Service Provider to version 2.5.4 or later.
3
Who is affected by CVE-2015-2684?
CVE-2015-2684 affects users of Shibboleth Service Provider versions before 2.5.4 and Debian GNU/Linux 7.0.
4
What type of attack is associated with CVE-2015-2684?
CVE-2015-2684 is associated with a denial of service attack that can crash the Service Provider.
5
What SAML message manipulation is involved in CVE-2015-2684?
CVE-2015-2684 involves remote authenticated users sending crafted SAML messages that exploit the vulnerability.