aboutsummaryrefslogtreecommitdiff
path: root/accessibility
diff options
context:
space:
mode:
authorPalle Girgensohn <girgen@FreeBSD.org>2015-07-23 16:24:25 +0000
committerPalle Girgensohn <girgen@FreeBSD.org>2015-07-23 16:24:25 +0000
commit7d7c2271f6c957574221e8746e5a356435cd114f (patch)
tree62df5949bd48fd9ac402081c242b4bc0cddbabd5 /accessibility
parent3067282daf95d00d30cd9d08337b583e871f298e (diff)
downloadports-2015Q2.tar.gz
ports-2015Q2.zip
Shibboleth SP software crashes on well-formed but invalid XML.2015Q2
The Service Provider software contains a code path with an uncaught exception that can be triggered by an unauthenticated attacker by supplying well-formed but schema-invalid XML in the form of SAML metadata or SAML protocol messages. The result is a crash and so causes a denial of service. You must rebuild opensaml and shibboleth with xmltooling-1.5.5 or later. The easiest way to do so is to update the whole chain including shibboleth-2.5.5 an opensaml2.5.5. URL: http://shibboleth.net/community/advisories/secadv_20150721.txt Security: CVE-2015-2684 Approved by: ports-secteam
Notes
Notes: svn path=/branches/2015Q2/; revision=392739
Diffstat (limited to 'accessibility')
0 files changed, 0 insertions, 0 deletions