Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly handle a 0 character in the subject or subjectAltName fields of a certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Shibboleth-sp | Internet2 | 1.3.1 (including) | 1.3.1 (including) |
Shibboleth-sp | Internet2 | 1.3.2 (including) | 1.3.2 (including) |
Shibboleth-sp | Internet2 | 1.3f (including) | 1.3f (including) |
Shibboleth-sp | Internet2 | 2.0 (including) | 2.0 (including) |
Shibboleth-sp | Internet2 | 2.1 (including) | 2.1 (including) |
Shibboleth-sp | Internet2 | 2.2 (including) | 2.2 (including) |
Opensaml | Ubuntu | hardy | * |
Opensaml | Ubuntu | intrepid | * |
Opensaml | Ubuntu | jaunty | * |
Shibboleth-sp | Ubuntu | hardy | * |
Shibboleth-sp | Ubuntu | intrepid | * |
Shibboleth-sp | Ubuntu | jaunty | * |
Shibboleth-sp | Ubuntu | upstream | * |
Xmltooling | Ubuntu | intrepid | * |
Xmltooling | Ubuntu | jaunty | * |
Xmltooling | Ubuntu | karmic | * |
Xmltooling | Ubuntu | upstream | * |