FreeBSD Bugzilla – Attachment 225493 Details for
Bug 256373
inform users via security/vuxml about the recent lasso vulnerability
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
vuxml entry
lasso.patch (text/plain), 1.20 KB, created by
rob2g2
on 2021-06-02 11:56:01 UTC
(
hide
)
Description:
vuxml entry
Filename:
MIME Type:
Creator:
rob2g2
Created:
2021-06-02 11:56:01 UTC
Size:
1.20 KB
patch
obsolete
>*** vuln.xml.orig Tue Jun 1 22:51:15 2021 >--- vuln.xml Tue Jun 1 23:03:23 2021 >*************** >*** 78 **** >--- 79,108 ---- >+ <vuln vid="417de1e6-c31b-11eb-9633-b42e99a1b9c3"> >+ <topic>lasso -- signature checking failure</topic> >+ <affects> >+ <package> >+ <name>lasso</name> >+ <range><lt>2.7.0</lt></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>entrouvert reports:</p> >+ <blockquote cite="https://git.entrouvert.org/lasso.git/tree/NEWS?id=v2.7.0"> >+ <p>When AuthnResponse messages are not signed (which is >+ permitted by the specifiation), all assertion's signatures should be >+ checked, but currently after the first signed assertion is checked all >+ following assertions are accepted without checking their signature, and >+ the last one is considered the main assertion.</p> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <cvename>CVE-2021-28091</cvename> >+ <url>https://git.entrouvert.org/lasso.git/tree/NEWS?id=v2.7.0</url> >+ </references> >+ <dates> >+ <discovery>2021-06-01</discovery> >+ <entry>2021-06-01</entry> >+ </dates> >+ </vuln> >+
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 256373
: 225493