9.3
CVSSv2

CVE-2009-3476

Published: 29/09/2009 Updated: 17/08/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in OpenSAML prior to 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x prior to 1.3.4, and XMLTooling prior to 1.2.2 as used in Internet2 Shibboleth Service Provider software 2.x prior to 2.2.1, allows remote malicious users to cause a denial of service and possibly execute arbitrary code via a malformed encoded URL.

Vulnerable Product Search on Vulmon Subscribe to Product

internet2 shibboleth-sp 1.3.2

internet2 shibboleth-sp 1.3.3

internet2 shibboleth-sp 1.3.1

internet2 shibboleth-sp 1.3f

internet2 opensaml 1.1

internet2 opensaml 1.1.1

internet2 xmltooling 1.1.0

internet2 xmltooling 1.0.1

internet2 xmltooling 1.1.1

internet2 xmltooling 1.2.0

internet2 xmltooling 1.2.1

internet2 shibboleth-sp 2.0

internet2 shibboleth-sp 2.1

internet2 shibboleth-sp 2.2