Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-31826

Опубликовано: 27 апр. 2021
Источник: debian

Описание

Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
shibboleth-spfixed3.2.2+dfsg1-1package

Примечания

  • https://shibboleth.net/community/advisories/secadv_20210426.txt

  • https://issues.shibboleth.net/jira/browse/SSPCPP-927

  • https://git.shibboleth.net/view/?p=cpp-sp.git;a=commit;h=5a47c3b9378f4c49392dd4d15189b70956f9f2ec

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.

CVSS3: 7.5
nvd
почти 5 лет назад

Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.

github
больше 3 лет назад

Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery feature. The flaw is exploitable (for a daemon crash) on systems not using this feature if a crafted cookie is supplied.

CVSS3: 7.5
fstec
почти 5 лет назад

Уязвимость функции восстановления сеанса компонента технологии аутентификации Shibboleth Service Provider, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании