LWN.net Logo

opensaml2: XML signature wrapping attack

Package(s):opensaml2 CVE #(s):CVE-2011-1411
Created:July 25, 2011 Updated:September 27, 2011
Description: From the Debian advisory:

Juraj Somorovsky, Andreas Mayer, Meiko Jensen, Florian Kohlar, Marco Kampmann and Joerg Schwenk discovered that Shibboleth, a federated web single sign-on system is vulnerable to XML signature wrapping attacks. More details can be found in the Shibboleth advisory at http://shibboleth.internet2.edu/security-advisories.html.

Alerts:
Fedora FEDORA-2011-12890 2011-09-18
Debian DSA-2284-1 2011-07-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds