PT-2009-5768 · Internet2 · Shibboleth Service Provider

Chris Ries

·

Publicado

2009-09-29

·

Atualizado

2009-09-30

·

CVE-2009-3475

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Internet2 Shibboleth Service Provider software versions 1.3.x through 1.3.2 Internet2 Shibboleth Service Provider software versions 2.x through 2.2.0
Description The issue arises when the software uses PKIX trust validation and fails to properly handle a '0' character in the subject or subjectAltName fields of a certificate. This allows remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Recommendations For versions 1.3.x through 1.3.2, update to version 1.3.3 or later. For versions 2.x through 2.2.0, update to version 2.2.1 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-3475
DSA-1895-1
DSA-1895-2
DSA-1896-1

Produtos afetados

Shibboleth Service Provider