Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-3474

Опубликовано: 29 сент. 2009
Источник: debian
EPSS Низкий

Описание

OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose, potentially weakening the intended security application of the certificate.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xmltoolingfixed1.2.2-1package
opensamlfixed3.0.0-2package
opensaml2fixed2.2.1-1package
shibboleth-spfixed3.0.2+dfsg1-2package
shibboleth-sp2fixed2.2.1+dfsg-1package
opensamlfixed1.1.1-2+lenny1lennypackage
opensaml2fixed2.0-2+lenny1lennypackage

EPSS

Процентиль: 79%
0.01289
Низкий

Связанные уязвимости

ubuntu
около 16 лет назад

OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose, potentially weakening the intended security application of the certificate.

nvd
около 16 лет назад

OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose, potentially weakening the intended security application of the certificate.

github
больше 3 лет назад

OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose, potentially weakening the intended security application of the certificate.

EPSS

Процентиль: 79%
0.01289
Низкий