MidnightBSD

Advisories for uninett

CVE-2012-4523 MEDIUM

radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
uninett radsecproxy 1.4.3
uninett radsecproxy *
uninett radsecproxy 1.0
uninett radsecproxy 1.3.1
uninett radsecproxy 1.5
uninett radsecproxy 1.4
uninett radsecproxy 1.4.2
uninett radsecproxy 1.4.1
uninett radsecproxy 1.2
uninett radsecproxy 1.3
uninett radsecproxy 1.1
CVE-2012-4566 MEDIUM

The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients, a different vulnerability than CVE-2012-4523.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-264,

Products Affected

Vendor Product Version
uninett radsecproxy 1.4.3
uninett radsecproxy 1.0
uninett radsecproxy 1.4
uninett radsecproxy 1.4.1
uninett radsecproxy 1.2
uninett radsecproxy 1.3
uninett radsecproxy 1.1
uninett radsecproxy *
uninett radsecproxy 1.3.1
uninett radsecproxy 1.5
uninett radsecproxy 1.4.2
uninett radsecproxy 1.6
CVE-2014-8566 MEDIUM

The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via unspecified vectors related to a "session overflow" involving "sessions overlapping in memory."

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
oracle linux 6
uninett mod_auth_mellon *
CVE-2014-8567 HIGH

The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-399,

Products Affected

Vendor Product Version
redhat enterprise_linux_server_tus 6.6
redhat enterprise_linux_server_eus 6.6
redhat enterprise_linux_server_aus 6.6
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_workstation 6.0
redhat enterprise_linux_server 6.0
uninett mod_auth_mellon *
CVE-2016-2145 MEDIUM

The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
fedoraproject fedora 23
uninett mod_auth_mellon *
CVE-2016-2146 MEDIUM

The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POST data.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
fedoraproject fedora 23
uninett mod_auth_mellon *
CVE-2017-6807 MEDIUM

mod_auth_mellon before 0.13.1 is vulnerable to a Cross-Site Session Transfer attack, where a user with access to one web site running on a server can copy their session cookie to a different web site on the same server to get access to that site.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
uninett mod_auth_mellon *