Lucene search

K
cve[email protected]CVE-2009-3476
HistorySep 29, 2009 - 11:30 p.m.

CVE-2009-3476

2009-09-2923:30:00
CWE-119
web.nvd.nist.gov
31
cve-2009-3476
buffer overflow
opensaml
denial of service
remote attackers
arbitrary code
malformed url
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.035 Low

EPSS

Percentile

91.5%

Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before 1.2.2 as used in Internet2 Shibboleth Service Provider software 2.x before 2.2.1, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed encoded URL.

Affected configurations

NVD
Node
internet2shibboleth-spMatch1.3.1
OR
internet2shibboleth-spMatch1.3.2
OR
internet2shibboleth-spMatch1.3.3
OR
internet2shibboleth-spMatch1.3f
AND
internet2opensamlMatch1.1
OR
internet2opensamlMatch1.1.1
Node
internet2xmltoolingMatch1.0.1
OR
internet2xmltoolingMatch1.1.0
OR
internet2xmltoolingMatch1.1.1
OR
internet2xmltoolingMatch1.2.0
OR
internet2xmltoolingMatch1.2.1
AND
internet2shibboleth-spMatch2.0
OR
internet2shibboleth-spMatch2.1
OR
internet2shibboleth-spMatch2.2

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.8 High

AI Score

Confidence

Low

0.035 Low

EPSS

Percentile

91.5%