Buffer Overflow Vulnerability in OpenSAML Affecting Internet2 Shibboleth Service Provider
CVE-2009-3476
Currently unrated
What is CVE-2009-3476?
A buffer overflow vulnerability exists in OpenSAML prior to version 1.1.3 and XMLTooling prior to version 1.2.2, as integrated into Internet2 Shibboleth Service Provider versions 1.3.x preceding 1.3.4 and 2.x preceding 2.2.1. This flaw enables remote attackers to potentially cause a denial of service and, under certain conditions, execute arbitrary code by supplying a malformed encoded URL.
