CVE-2009-3474

Source
https://nvd.nist.gov/vuln/detail/CVE-2009-3474
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2009-3474.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2009-3474
Related
Published
2009-09-29T23:30:00Z
Modified
2024-11-21T01:07:27Z
Summary
[none]
Details

OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribute, which allows remote attackers to use a certificate for both signing and encryption when it is designated for just one purpose, potentially weakening the intended security application of the certificate.

References

Affected packages

Debian:11 / opensaml

Package

Name
opensaml
Purl
pkg:deb/debian/opensaml?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / opensaml

Package

Name
opensaml
Purl
pkg:deb/debian/opensaml?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / opensaml

Package

Name
opensaml
Purl
pkg:deb/debian/opensaml?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.0-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / shibboleth-sp

Package

Name
shibboleth-sp
Purl
pkg:deb/debian/shibboleth-sp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.2+dfsg1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / shibboleth-sp

Package

Name
shibboleth-sp
Purl
pkg:deb/debian/shibboleth-sp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.2+dfsg1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / shibboleth-sp

Package

Name
shibboleth-sp
Purl
pkg:deb/debian/shibboleth-sp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.2+dfsg1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:11 / xmltooling

Package

Name
xmltooling
Purl
pkg:deb/debian/xmltooling?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / xmltooling

Package

Name
xmltooling
Purl
pkg:deb/debian/xmltooling?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / xmltooling

Package

Name
xmltooling
Purl
pkg:deb/debian/xmltooling?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}