Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <50D33ECA.3090006@lab.b-care.net>
Date: Thu, 20 Dec 2012 17:37:30 +0100
From: Frédéric Basse <frederic.basse@....b-care.net>
To: oss-security@...ts.openwall.com
Subject: Re: [CVE-2012-6426] LemonLDAP-NG SAML XML Signature
 Wrapping

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[CVE-2012-6426] LemonLDAP-NG SAML XML Signature Wrapping
_______________________________________________________________________
Summary:
LemonLDAP-NG <=1.2.2 is prone to a security vulnerability involving
XML signature wrapping in authentication process.

Successful exploits may allow unauthenticated attackers to construct
specially crafted messages that can be successfully verified and
contain arbitrary content.

This may lead to authentication bypass.
_______________________________________________________________________
Details:
Due to a bad use of Lasso library, SAML signatures are never checked,
even if SP forces signature check.
____________________________________________________________________
CVSS Version 2 Metrics:
Access Vector: Network exploitable
Access Complexity: Low
Authentication: Not required to exploit
Impact Type:Allows unauthorized disclosure of information; Allows
unauthorized modification
_______________________________________________________________________
Disclosure Timeline:
2012-11-08 Vendor contacted
2012-12-18 Vendor: fixed issue in svn r2698
2012-12-19 CVE-2012-6426 assigned
2012-12-20 Public advisory
2012-12-21 EoW
_______________________________________________________________________
References:
http://jira.ow2.org/browse/LEMONLDAP-570
_______________________________________________________________________
Frédéric Basse - Thales Communications & Security
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQEcBAEBAgAGBQJQ0z7KAAoJEG39VVx5rCjDjjUIAJz8M4OifN9cHf3W1qBwxFex
CU3jUIGXb1H2N2OVH4DnU1xdFfm8Hr4nEbvSl+3yKJbIWAAPXx3Y5Ok9+LypE+Rb
OrPRD9OJTat4wUj1SVbIh1bh1XWytRTq4i9pBE/F/86vyIJuQL9Hyya8ETSQoC6P
FUrKEesHvKJetICPCqsiMuJiCstedEvgdGhkMhrDqaEkZTDkvbaZysxuJ3JSQ6Pq
CioSQS2qB5U+IKJX2OKix1rR4ruaCoQmOq0qmRSr+8+a0dgP0Zf/w02KaXimuYwI
oKBmiOTavr8NhQl45QGjVMZi3jMKs8qmxWul5/GE6mH7GqI8SfdvQxZC+iHHxQo=
=IgwQ
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.