Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 08 Nov 2013 12:25:10 -0700
From: Kurt Seifried <kseifried@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: drupalauth module for simpleSAMLphp
 trivial impersonation

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 11/05/2013 01:54 AM, Thijs Kinkhorst wrote:
> Hi,
> 
> Alan Barrett reported an issue in the drupalauth module for simpleSAMLphp,
> which takes the username out of a cookie which is obviously under control
> of the user.
> 
> Report and patch:
> http://code.google.com/p/drupalauth/issues/detail?id=9
> 
> (Note that this is an independently developed module not part of the
> simpleSAMLphp core distribution. Note also that this module is used for
> Drupal as an authentication source, and is not related to using Drupal
> with simpleSAMLphp as an SP).
> 
> 
> Cheers,
> Thijs
> 

Please use CVE-2013-4552 for this issue.

- -- 
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.15 (GNU/Linux)

iQIcBAEBAgAGBQJSfTqWAAoJEBYNRVNeJnmT5NAQAMQOyN4OE1whskacsjO8mBMH
iWmRZNjFA2ab/Wjhn4i6uPKEeVtx556EgavwNYkihsXGifi5wNpjHmWAbYxISSvE
XgLZvrh4lF9+v6fEDL5KSjvnGDEAdIwu5/aw1nC9CqIDtk7xoROIpCPIZJOT7y9l
TUVr+I0Dn6EMeCab3OILpUXtOyyxB+2HWlViBHdJSmxPE7qI9XeOib1IQ+wuHU+c
h0/tuNOU8ATrJL4/LP1AnmFkBZvuNzEZD1JhOPn5DvbCY1CVHrW4BTM0OpY0PSt4
UPHJhYUqOZZisxqAOAMKEsm36G1EoKe/grMfI+YGdQjPhudncoZyHQzP/2F8EPn4
do3SRLd/c21w7LnKuoJpbJvjFwMYBmlx6CJB6kV0QdzQfPZ6wHR3Jpop1awsEB0f
vYS1eZyJ7swfgGWDgmpr413jp9H3wb17Pl0J3kNm96m8AVWQL2FO4oXHzI+xn84J
3f99vnB76Wha35NsVLkkNH74BLQbMzyVQKS4Uo5jkvOCubIOcjAZieiB4s1COmCG
c7oKjquHEkoJuEeUElx0zQCQYQ++U+z6dFoBo10uSNI8NGbMjALFI3eEQ7/uB/BT
TpqE3RWah433NzEs3uBnakvA0B1h/SPE3C1ijCSQaH1hyUNRVX1eMk7pSenk+RAI
xemOhTv7B7j4Wl6dDRpm
=6UjU
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.