CVE-2010-2450

NameCVE-2010-2450
DescriptionThe keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs571631

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
shibboleth-sp (PTS)buster, buster (security)3.0.4+dfsg1-1+deb10u2fixed
bullseye3.2.2+dfsg1-1fixed
trixie, bookworm3.4.1+dfsg-2fixed
sid3.4.1+dfsg-2.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
shibboleth-spsource(unstable)(not affected)
shibboleth-sp2source(unstable)2.3.1+dfsg-2low571631

Notes

[lenny] - shibboleth-sp2 <no-dsa> (Minor issue)
- shibboleth-sp <not-affected> (Vulnerable code not present)

Search for package or bug name: Reporting problems