Bug 1068685 - (CVE-2017-16853) VUL-0: CVE-2017-16853: opensaml: The DynamicMetadataProvider class fails to properly configure itself with the MetadataFilter plugins, allowing active attackers to MITM etc
(CVE-2017-16853)
VUL-0: CVE-2017-16853: opensaml: The DynamicMetadataProvider class fails to p...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/195135/
CVSSv2:SUSE:CVE-2017-16853:7.1:(AV:N/...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-11-17 12:20 UTC by Johannes Segitz
Modified: 2017-12-08 11:12 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2017-11-17 12:20:16 UTC
CVE-2017-16853

The DynamicMetadataProvider class in
saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML
before 2.6.1 fails to properly configure itself with the MetadataFilter plugins
and does not perform critical security checks such as signature verification,
enforcement of validity periods, and other checks specific to deployments, aka
CPPOST-105.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16853
http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-16853.html
http://www.debian.org/security/2017/dsa-4039
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881856
https://git.shibboleth.net/view/?p=cpp-opensaml.git;a=commit;h=6182b0acf2df670e75423c2ed7afe6950ef11c9d
Comment 1 Kristyna Streitova 2017-11-21 12:22:17 UTC
Done.

|    Codestream    |   Request    |
|------------------|--------------|
| SLE12SP1         | #146768      |
| openSUSE:Leap    | via SLE12SP1 |
| openSUSE:Factory | #544152      |

I'm reassigning it back to the security-team.
Comment 3 Swamp Workflow Management 2017-12-07 20:12:14 UTC
SUSE-SU-2017:3234-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1068685
CVE References: CVE-2017-16853
Sources used:
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    opensaml-2.5.5-3.3.1
SUSE Linux Enterprise Software Development Kit 12-SP2 (src):    opensaml-2.5.5-3.3.1
SUSE Linux Enterprise Server for Raspberry Pi 12-SP2 (src):    opensaml-2.5.5-3.3.1
SUSE Linux Enterprise Server 12-SP3 (src):    opensaml-2.5.5-3.3.1
SUSE Linux Enterprise Server 12-SP2 (src):    opensaml-2.5.5-3.3.1
Comment 4 Andreas Stieger 2017-12-08 07:30:32 UTC
done
Comment 5 Swamp Workflow Management 2017-12-08 11:12:43 UTC
openSUSE-SU-2017:3241-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1068685
CVE References: CVE-2017-16853
Sources used:
openSUSE Leap 42.3 (src):    opensaml-2.5.5-6.1
openSUSE Leap 42.2 (src):    opensaml-2.5.5-3.3.1