Shibboleth SP crashing during signature computation
Cantor, Scott
cantor.2 at osu.edu
Fri Jul 13 13:08:34 EDT 2012
On 7/13/12 12:55 PM, "Rob Whitener" <rob.whitener at audaxhealth.com> wrote:
>
>So I am guessing they are forcing us to sign our requests. I will see
>what sort of hell we will have to go through to get them to turn that off
>(we are very small, they are very big).
Well, the first step is to find out if it matters. Change it and see if
the crash is avoided. If not, it's something else anyway.
>Given that we are on a downleveled version of both Shibboleth and Ubuntu,
>will dropping in the patched version of libxml-security help us close the
>security hole or will we need to upgrade everything.
I don't know anything about the packages you're using. An unpatched set of
2.3 code is wide open to attack for reasons that have nothing to do with
your original issue. The advisory on xmlsec was a denial of service issue,
but the wrapping attack is a remote exploit.
Debian's packages are maintained with security fixes backported and you
would see those advisories addressed in the change log of those packages.
And there are Debian packages available for V2.4 in any case.
-- Scott
More information about the users
mailing list