4
CVSSv2

CVE-2015-2684

Published: 31/03/2015 Updated: 03/12/2016
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P

Vulnerability Summary

Shibboleth Service Provider (SP) prior to 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message.

Vulnerable Product Search on Vulmon Subscribe to Product

shibboleth service provider

debian debian linux 7.0

Vendor Advisories

A denial of service vulnerability was found in the Shibboleth (an federated identity framework) Service Provider When processing certain malformed SAML message generated by an authenticated attacker, the daemon could crash For the stable distribution (wheezy), this problem has been fixed in version 243+dfsg-5+deb7u1 For the upcoming stable dis ...