|
Message-ID: <50D33ECA.3090006@lab.b-care.net> Date: Thu, 20 Dec 2012 17:37:30 +0100 From: Frédéric Basse <frederic.basse@....b-care.net> To: oss-security@...ts.openwall.com Subject: Re: [CVE-2012-6426] LemonLDAP-NG SAML XML Signature Wrapping -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [CVE-2012-6426] LemonLDAP-NG SAML XML Signature Wrapping _______________________________________________________________________ Summary: LemonLDAP-NG <=1.2.2 is prone to a security vulnerability involving XML signature wrapping in authentication process. Successful exploits may allow unauthenticated attackers to construct specially crafted messages that can be successfully verified and contain arbitrary content. This may lead to authentication bypass. _______________________________________________________________________ Details: Due to a bad use of Lasso library, SAML signatures are never checked, even if SP forces signature check. ____________________________________________________________________ CVSS Version 2 Metrics: Access Vector: Network exploitable Access Complexity: Low Authentication: Not required to exploit Impact Type:Allows unauthorized disclosure of information; Allows unauthorized modification _______________________________________________________________________ Disclosure Timeline: 2012-11-08 Vendor contacted 2012-12-18 Vendor: fixed issue in svn r2698 2012-12-19 CVE-2012-6426 assigned 2012-12-20 Public advisory 2012-12-21 EoW _______________________________________________________________________ References: http://jira.ow2.org/browse/LEMONLDAP-570 _______________________________________________________________________ Frédéric Basse - Thales Communications & Security -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ iQEcBAEBAgAGBQJQ0z7KAAoJEG39VVx5rCjDjjUIAJz8M4OifN9cHf3W1qBwxFex CU3jUIGXb1H2N2OVH4DnU1xdFfm8Hr4nEbvSl+3yKJbIWAAPXx3Y5Ok9+LypE+Rb OrPRD9OJTat4wUj1SVbIh1bh1XWytRTq4i9pBE/F/86vyIJuQL9Hyya8ETSQoC6P FUrKEesHvKJetICPCqsiMuJiCstedEvgdGhkMhrDqaEkZTDkvbaZysxuJ3JSQ6Pq CioSQS2qB5U+IKJX2OKix1rR4ruaCoQmOq0qmRSr+8+a0dgP0Zf/w02KaXimuYwI oKBmiOTavr8NhQl45QGjVMZi3jMKs8qmxWul5/GE6mH7GqI8SfdvQxZC+iHHxQo= =IgwQ -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.