[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2014:1803-01 -- Redhat mod_auth_mellon

ID: oval:org.secpod.oval:def:501446Date: (C)2014-11-14   (M)2023-07-28
Class: PATCHFamily: unix




mod_auth_mellon provides a SAML 2.0 authentication module for the Apache HTTP Server. An information disclosure flaw was found in mod_auth_mellon"s session handling that could lead to sessions overlapping in memory. A remote attacker could potentially use this flaw to obtain data from another user"s session. It was found that uninitialized data could be read when processing a user"s logout request. By attempting to log out, a user could possibly cause the Apache HTTP Server to crash. Red Hat would like to thank the mod_auth_mellon team for reporting these issues. Upstream acknowledges Matthew Slowe as the original reporter of CVE-2014-8566. All users of mod_auth_mellon are advised to upgrade to this updated package, which contains a backported patch to correct these issues.

Platform:
Red Hat Enterprise Linux 6
Product:
mod_auth_mellon
Reference:
RHSA-2014:1803-01
CVE-2014-8566
CVE-2014-8567
CVE    2
CVE-2014-8567
CVE-2014-8566
CPE    2
cpe:/o:redhat:enterprise_linux:6
cpe:/a:mod_auth_mellon:mod_auth_mellon

© SecPod Technologies