Debian DSA-4872-1 : shibboleth-sp - security update

high Nessus Plugin ID 147904

Synopsis

The remote Debian host is missing a security-related update.

Description

Toni Huttunen discovered that the Shibboleth service provider's template engine used to render error pages could be abused for phishing attacks.

For additional information please refer to the upstream advisory at https://shibboleth.net/community/advisories/secadv_20210317.txt

Solution

Upgrade the shibboleth-sp packages.

For the stable distribution (buster), this problem has been fixed in version 3.0.4+dfsg1-1+deb10u1.

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=985405

https://shibboleth.net/community/advisories/secadv_20210317.txt

http://www.nessus.org/u?82c1ec06

https://packages.debian.org/source/buster/shibboleth-sp

https://www.debian.org/security/2021/dsa-4872

Plugin Details

Severity: High

ID: 147904

File Name: debian_DSA-4872.nasl

Version: 1.1

Type: local

Agent: unix

Published: 3/19/2021

Updated: 3/19/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Vulnerability Information

CPE: cpe:/o:debian:debian_linux:10.0, p-cpe:/a:debian:debian_linux:shibboleth-sp

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 3/18/2021

Vulnerability Publication Date: 3/18/2021

Reference Information

DSA: 4872