Shibboleth Service Provider Security Advisory [18 June 2013]
Cantor, Scott
cantor.2 at osu.edu
Mon Jun 17 23:11:53 EDT 2013
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Shibboleth Service Provider Security Advisory [18 June 2013]
An updated version of the Shibboleth Service Provider software
is now available which includes an updated version of a dependency
that corrects a security issue.
Platforms on which xml-security-c is an OS-supplied component,
such as Debian Linux, will need to ensure their vendor has supplied
an updated package to correct the issue.
Shibboleth SP heap overflow processing InclusiveNamespace PrefixList
====================================================================
The Apache Santuario XML Security for C++ library contained a heap
overflow in the processing of XML content related to the
verification of signed XML such as SAML assertions. This could in
the worst case lead to the possibility for a remote, unauthenticated
attacker to cause arbitrary code execution within the shibd process.
The SP software is not the source of the vulnerability, and the
fix required is contained solely in the xml-security-c library.
However, packaging and binary compatibility considerations typically
mean that older versions cannot always be fixed without upgrading
(unless built by hand).
The version of xml-security-c containing the fix is V1.7.1.
That vulnerability has been published as CVE-2013-2156.
Recommendations
===============
Ensure that V1.7.1 or later of the xml-security-c library is used.
For Windows installations, V2.5.2 of the Shibboleth SP is now
available and contains updates to several libraries, including this
fix. All V2.5.x installations should be upgradeable to this release.
Older Windows versions have been unsupported since late 2012 and are
not upgradeable without removing them, and installing V2.5.2.
Linux installations relying on official RPM packages can upgrade to
the latest package versions to obtain the fix. If your system already
includes V1.7.0 of the xml-security-c library, then you MAY address
the issue by updating only that package. Shibboleth and OpenSAML
packages built against older versions, such as V1.6.x, will not
be binary-compatible with the newer version.
Sites that have deployed by building their own copy of xml-security-c
should ensure that they upgrade to V1.7.1 of that package, or patch
older versions as desired.
Sites that rely on an OS-supplied version of xml-security-c will need
to contact their OS vendor for a fixed version, or manually build a
new or patched version.
Credits
=======
Thanks to James Forshaw of Context Information Security for reporting
the issue to the Apache Santuario project.
URL for this Security Advisory:
http://shibboleth.net/community/advisories/secadv_20130718.txt
URL for the vulnerability:
http://santuario.apache.org/secadv.data/CVE-2013-2156.txt
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.13 (Darwin)
iQIcBAEBCgAGBQJRv8ElAAoJEDeLhFQCJ3li9x0P/0V08MtqHCPdELRsa+c6vKo2
KrRngudlo4nHLCLpj7Q3hicoxBbiq+ACw6wfzj5UAzvDpRvEY0/SfzLs1w594gXb
eNbixbtoqjFiCsTq04FSlqtDzHROcYhsJ2nHaMkqCzjXTXmYfIsDqpnFyapboWSz
y2jIV5XT2sJ/UdjaWYQiQ/dxuJ0OK2ihZZex+XGAcOHjBMrZEaoc+Yv5qfvwjjQT
S9NZ52xth3S+H5me9Nx1TGiLRdHOTU30L0hEmcL1TRnCz2oMzH72G56WBtHP2BUN
ky3qgb4D8p5Th2uMXGrGsi61tE2tHylv7xuMGQbQolbDkkNuWk+R+Os39rK0Ga51
J+kcHZNihAbuzp/XBkQeKdgtARlXSbF5+yBXu+H8Y4PD22H4b9B7QH9Oxbbc/wLp
jyzxWlDscW2TKC8FoysORuBGGgADQe1tx6VE7iBW2ZVAtzRTxNGgYFdhMo8kIUl8
wZT2Gty206cEBLz+EJL9eW6UMDNmc22GnGIDcX0Mew73I2buVcVoiXHMm0ewATj/
MWm9HeQiZn0yvjlqMM0F6DzbhdCyovp6R6pNNrIDntFLY0Jcz6x/8Mb5KjYwiVKm
iVmQg5XbybID4RfbFpH0Av6B4Hsr3KGRJFNIsMAjLmWA6jySwfHwlXnwzZDJlKmP
CNLyZLnnXea7imICBZtH
=HxtU
-----END PGP SIGNATURE-----
More information about the announce
mailing list