Where
-Infinity
0

The modauthmellon module for the Apache HTTP Server is an authentication service that implements the SAML 2.0 federation protocol. The module grants access based on the attributes received in assertions generated by an IdP server.<br>Security Fix(es):<br><li> modauthmellon: authentication bypass in ECP flow (CVE-2019-3878)</li> <li> modauthmellon: open redirect in logout url when using URLs with backslashes (CVE-2019-3877)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.<br>Bug Fix(es):<br><li> modauthmellon Cert files name wrong when hostname contains a number (fixed in upstream package) (BZ#1697487)</li>

Remedy

<tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> mod_auth_mellon-0.14.0-2.el7_6.4.src.rpm </td> <td class="checksum">SHA-256: 4c06720c0307320e102af15a72608fc680b01178b86135d48447878e4c2d3ccb</td> </tr> <tr> <th colspan="2">ppc64le</th> </tr> <tr> <td class="name"> mod_auth_mellon-0.14.0-2.el7_6.4.ppc64le.rpm </td> <td class="checksum">SHA-256: f863f5c303836eb12ae1f7e52f099237bae3950a79c0ab5ce1b9cf8ea7aa69f7</td> </tr> <tr> <td class="name"> mod_auth_mellon-debuginfo-0.14.0-2.el7_6.4.ppc64le.rpm </td> <td class="checksum">SHA-256: 1ef22f0de45e3b2df6f8b3b26e89a3d99b09c3ea3f57766aa64d47dfbc129e3d</td> </tr> <tr> <td class="name"> mod_auth_mellon-debuginfo-0.14.0-2.el7_6.4.ppc64le.rpm </td> <td class="checksum">SHA-256: 1ef22f0de45e3b2df6f8b3b26e89a3d99b09c3ea3f57766aa64d47dfbc129e3d</td> </tr> <tr> <td class="name"> mod_auth_mellon-diagnostics-0.14.0-2.el7_6.4.ppc64le.rpm </td> <td class="checksum">SHA-256: efb21c78914b2c556e4fce2df6f887e0417fbcca4a9e9f3076d810cc963d6137</td> </tr> </tbody>Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 7.6 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> mod_auth_mellon-0.14.0-2.el7_6.4.src.rpm </td> <td class="checksum">SHA-256: 4c06720c0307320e102af15a72608fc680b01178b86135d48447878e4c2d3ccb</td> </tr> <tr> <th colspan="2">x86_64</th> </tr> <tr> <td class="name"> mod_auth_mellon-0.14.0-2.el7_6.4.x86_64.rpm </td> <td class="checksum">SHA-256: 3877a62d83219303048414223c56504c34067f649110549f2fbb127f7427531e</td> </tr> <tr> <td class="name"> mod_auth_mellon-debuginfo-0.14.0-2.el7_6.4.x86_64.rpm </td> <td class="checksum">SHA-256: 721236b704048938286bde8122b41e92a0897754ced8222028f15650f768a53a</td> </tr> <tr> <td class="name"> mod_auth_mellon-debuginfo-0.14.0-2.el7_6.4.x86_64.rpm </td> <td class="checksum">SHA-256: 721236b704048938286bde8122b41e92a0897754ced8222028f15650f768a53a</td> </tr> <tr> <td class="name"> mod_auth_mellon-diagnostics-0.14.0-2.el7_6.4.x86_64.rpm </td> <td class="checksum">SHA-256: 8f1d38cb72311ad87683d19cc4506f2f556299e49df9ad427fd0ec43f06af9ff</td> </tr> </tbody>Red Hat Enterprise Linux for IBM System z (Structure A) 7 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> mod_auth_mellon-0.14.0-2.el7_6.4.src.rpm </td> <td class="checksum">SHA-256: 4c06720c0307320e102af15a72608fc680b01178b86135d48447878e4c2d3ccb</td> </tr> <tr> <th colspan="2">s390x</th> </tr> <tr> <td class="name"> mod_auth_mellon-0.14.0-2.el7_6.4.s390x.rpm </td> <td class="checksum">SHA-256: e4eb79d3ee21aa7b82732387fd97e4b0d309d95dd6bbc7244a9f2b73018db15d</td> </tr> <tr> <td class="name"> mod_auth_mellon-debuginfo-0.14.0-2.el7_6.4.s390x.rpm </td> <td class="checksum">SHA-256: e993f7ac666a84469373095ff9c49f982ff0caf808bc7d7323fee4e48c15b547</td> </tr> <tr> <td class="name"> mod_auth_mellon-debuginfo-0.14.0-2.el7_6.4.s390x.rpm </td> <td class="checksum">SHA-256: e993f7ac666a84469373095ff9c49f982ff0caf808bc7d7323fee4e48c15b547</td> </tr> <tr> <td class="name"> mod_auth_mellon-diagnostics-0.14.0-2.el7_6.4.s390x.rpm </td> <td class="checksum">SHA-256: 2568cf489b8c4cdd3f062645dfedffcaf270eb92e7b2bbbb5b986f41b470a6a2</td> </tr> </tbody>Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> mod_auth_mellon-0.14.0-2.el7_6.4.src.rpm </td> <td class="checksum">SHA-256: 4c06720c0307320e102af15a72608fc680b01178b86135d48447878e4c2d3ccb</td> </tr> <tr> <th colspan="2">ppc64</th> </tr> <tr> <td class="name"> mod_auth_mellon-0.14.0-2.el7_6.4.ppc64.rpm </td> <td class="checksum">SHA-256: b1ba3a67fa3b50cde76070fbc02502e1a983cf8c0366e006552bc0fecdc41738</td> </tr> <tr> <td class="name"> mod_auth_mellon-debuginfo-0.14.0-2.el7_6.4.ppc64.rpm </td> <td class="checksum">SHA-256: 3be876260836968ce4cc68e4ae60c45920c1675167ae48fd89ba88a9ab3d6888</td> </tr> <tr> <td class="name"> mod_auth_mellon-debuginfo-0.14.0-2.el7_6.4.ppc64.rpm </td> <td class="checksum">SHA-256: 3be876260836968ce4cc68e4ae60c45920c1675167ae48fd89ba88a9ab3d6888</td> </tr> <tr> <td class="name"> mod_auth_mellon-diagnostics-0.14.0-2.el7_6.4.ppc64.rpm </td> <td class="checksum">SHA-256: 2d5ad897cdab16bb85998461afde83711a6e074b713bd3bcd5c3d57f654f6948</td> </tr> </tbody>Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 <tbody><tr> <th colspan="2">SRPM</th> </tr> <tr> <td class="name"> mod_auth_mellon-0.14.0-2.el7_6.4.src.rpm </td> <td class="checksum">SHA-256: 4c06720c0307320e102af15a72608fc680b01178b86135d48447878e4c2d3ccb</td> </tr> <tr> <th colspan="2">ppc64le</th> </tr> <tr> <td class="name"> mod_auth_mellon-0.14.0-2.el7_6.4.ppc64le.rpm </td> <td class="checksum">SHA-256: f863f5c303836eb12ae1f7e52f099237bae3950a79c0ab5ce1b9cf8ea7aa69f7</td> </tr> <tr> <td class="name"> mod_auth_mellon-debuginfo-0.14.0-2.el7_6.4.ppc64le.rpm </td> <td class="checksum">SHA-256: 1ef22f0de45e3b2df6f8b3b26e89a3d99b09c3ea3f57766aa64d47dfbc129e3d</td> </tr> <tr> <td class="name"> mod_auth_mellon-debuginfo-0.14.0-2.el7_6.4.ppc64le.rpm </td> <td class="checksum">SHA-256: 1ef22f0de45e3b2df6f8b3b26e89a3d99b09c3ea3f57766aa64d47dfbc129e3d</td> </tr> <tr> <td class="name"> mod_auth_mellon-diagnostics-0.14.0-2.el7_6.4.ppc64le.rpm </td> <td class="checksum">SHA-256: efb21c78914b2c556e4fce2df6f887e0417fbcca4a9e9f3076d810cc963d6137</td> </tr> </tbody>
First published (updated )
Severity
7.5
Buffer Overflow
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

The amreadpostdata function in modauthmellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POST data.

First published (updated )
Severity
7.5
Input Validation
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

The amreadpostdata function in modauthmellon before 0.11.1 does not check if the apgetclientblock function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST data.

First published (updated )
Severity
6.4
Infoleak
AV:N/AC:L/Au:N/C:P/I:N/A:P

The modauthmellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."

First published (updated )
Severity
9.4
AV:N/AC:L/Au:N/C:N/I:C/A:C

The modauthmellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203