CVE-2017-16852

NameCVE-2017-16852
Descriptionshibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka SSPCPP-763.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-1179-1, DSA-4038-1
Debian Bugs881857

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
shibboleth-sp2 (PTS)jessie, jessie (lts)2.5.3+dfsg-2+deb8u2fixed
stretch (security), stretch (lts), stretch2.6.0+dfsg1-4+deb9u2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
shibboleth-sp2sourcewheezy2.4.3+dfsg-5+deb7u2DLA-1179-1
shibboleth-sp2sourcejessie2.5.3+dfsg-2+deb8u1DSA-4038-1
shibboleth-sp2sourcestretch2.6.0+dfsg1-4+deb9u1DSA-4038-1
shibboleth-sp2source(unstable)2.6.1+dfsg1-1881857

Notes

https://git.shibboleth.net/view/?p=cpp-sp.git;a=commit;h=b66cceb0e992c351ad5e2c665229ede82f261b16
https://shibboleth.net/community/advisories/secadv_20171115.txt

Search for package or bug name: Reporting problems