Does CVE-2015-0235 (GHOST) affect Shibboleth SP?
Cantor, Scott
cantor.2 at osu.edu
Sun Feb 8 12:51:06 EST 2015
> Does CVE-2015-0235 (GHOST) vulnerability affect Shibboleth SP?
> I don't think so but I am not convinced.
The SP does not contact any service it hasn't been configured with metadata to access, unless the Dynamic metadata provider is used in a mode that involves self-publishing metadata behind the entityID itself. Otherwise any host lookups are to names in metadata. If you allow untrusted metadata (by which I mean not verifying it properly, or using sources that aren't trustworthy), then you'd have a potential vulnerability.
-- Scott
More information about the users
mailing list