CVE-2017-16852

NameCVE-2017-16852
Descriptionshibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification, enforcement of validity periods, and other checks specific to deployments, aka SSPCPP-763.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1179-1, DSA-4038-1
NVD severitymedium (attack range: remote)
Debian Bugs881857

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
shibboleth-sp2 (PTS)jessie (security), jessie2.5.3+dfsg-2+deb8u1fixed
stretch (security), stretch2.6.0+dfsg1-4+deb9u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
shibboleth-sp2source(unstable)2.6.1+dfsg1-1medium881857
shibboleth-sp2sourcejessie2.5.3+dfsg-2+deb8u1mediumDSA-4038-1
shibboleth-sp2sourcestretch2.6.0+dfsg1-4+deb9u1mediumDSA-4038-1
shibboleth-sp2sourcewheezy2.4.3+dfsg-5+deb7u2mediumDLA-1179-1

Notes

https://git.shibboleth.net/view/?p=cpp-sp.git;a=commit;h=b66cceb0e992c351ad5e2c665229ede82f261b16
https://shibboleth.net/community/advisories/secadv_20171115.txt

Search for package or bug name: Reporting problems