CVE-2010-2450

NameCVE-2010-2450
DescriptionThe keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium
Debian Bugs571631

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
shibboleth-sp (PTS)buster3.0.4+dfsg1-1fixed
bullseye, sid3.1.0+dfsg1-2fixed
shibboleth-sp2 (PTS)stretch (security), stretch2.6.0+dfsg1-4+deb9u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
shibboleth-spsource(unstable)(not affected)
shibboleth-sp2source(unstable)2.3.1+dfsg-2low571631

Notes

[lenny] - shibboleth-sp2 <no-dsa> (Minor issue)
- shibboleth-sp <not-affected> (Vulnerable code not present)

Search for package or bug name: Reporting problems