[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195521

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2014:1803 -- centos 6 mod_auth_mellon

ID: oval:org.secpod.oval:def:203480Date: (C)2014-11-14   (M)2023-07-28
Class: PATCHFamily: unix




mod_auth_mellon provides a SAML 2.0 authentication module for the Apache HTTP Server. An information disclosure flaw was found in mod_auth_mellon"s session handling that could lead to sessions overlapping in memory. A remote attacker could potentially use this flaw to obtain data from another user"s session. It was found that uninitialized data could be read when processing a user"s logout request. By attempting to log out, a user could possibly cause the Apache HTTP Server to crash. Red Hat would like to thank the mod_auth_mellon team for reporting these issues. Upstream acknowledges Matthew Slowe as the original reporter of CVE-2014-8566. All users of mod_auth_mellon are advised to upgrade to this updated package, which contains a backported patch to correct these issues.

Platform:
CentOS 6
Product:
mod_auth_mellon
Reference:
CESA-2014:1803
CVE-2014-8566
CVE-2014-8567
CVE    2
CVE-2014-8567
CVE-2014-8566
CPE    2
cpe:/o:centos:centos:6
cpe:/a:mod_auth_mellon:mod_auth_mellon

© SecPod Technologies