Does CVE-2015-0235 (GHOST) affect Shibboleth SP?

Cantor, Scott cantor.2 at osu.edu
Sun Feb 8 12:51:06 EST 2015


> Does CVE-2015-0235 (GHOST) vulnerability affect Shibboleth SP?
> I don't think so but I am not convinced.

The SP does not contact any service it hasn't been configured with metadata to access, unless the Dynamic metadata provider is used in a mode that involves self-publishing metadata behind the entityID itself. Otherwise any host lookups are to names in metadata. If you allow untrusted metadata (by which I mean not verifying it properly, or using sources that aren't trustworthy), then you'd have a potential vulnerability.

-- Scott



More information about the users mailing list