Vulnerability CVE-2009-3474


Published: 2009-09-29   Modified: 2012-02-13

Description:
OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose, potentially weakening the intended security application of the certificate.

Type:

CWE-310

(Cryptographic Issues)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Internet2 -> Opensaml 
Internet2 -> Shibboleth-sp 
Internet2 -> Xmltooling 

 References:
http://www.securityfocus.com/bid/36516
http://www.debian.org/security/2009/dsa-1896
http://www.debian.org/security/2009/dsa-1895
http://shibboleth.internet2.edu/secadv/secadv_20090817a.txt
https://bugs.internet2.edu/jira/browse/CPPOST-28
http://xforce.iss.net/xforce/xfdb/53474
http://secunia.com/advisories/36876
http://secunia.com/advisories/36868
http://secunia.com/advisories/36855

Copyright 2024, cxsecurity.com

 

Back to Top