Buffer Overflow Vulnerability in OpenSAML Affecting Internet2 Shibboleth Service Provider
CVE-2009-3476

Currently unrated

Key Information:

Vendor

Internet2

Vendor
CVE Published:
29 September 2009

What is CVE-2009-3476?

A buffer overflow vulnerability exists in OpenSAML prior to version 1.1.3 and XMLTooling prior to version 1.2.2, as integrated into Internet2 Shibboleth Service Provider versions 1.3.x preceding 1.3.4 and 2.x preceding 2.2.1. This flaw enables remote attackers to potentially cause a denial of service and, under certain conditions, execute arbitrary code by supplying a malformed encoded URL.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.