mod_auth_mellon-0.14.0-2.el7.4

エラータID: AXSA:2019-3863:02

Release date: 
Sunday, May 5, 2019 - 14:20
Subject: 
mod_auth_mellon-0.14.0-2.el7.4
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

The mod_auth_mellon module for the Apache HTTP Server is an authentication service that implements the SAML 2.0 federation protocol. The module grants access based on the attributes received in assertions generated by an IdP server.

Security Fix(es):

* mod_auth_mellon: authentication bypass in ECP flow (CVE-2019-3878)

* mod_auth_mellon: open redirect in logout url when using URLs with backslashes (CVE-2019-3877)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

* mod_auth_mellon Cert files name wrong when hostname contains a number (fixed in upstream package) (BZ#1697487)

CVE-2019-3877
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect URL validation logic in apr_uri_parse function.
CVE-2019-3878
A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), adding special HTTP headers that are normally used to start the special SAML ECP (non-browser based) can be used to bypass authentication.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. mod_auth_mellon-0.14.0-2.el7.4.src.rpm
    MD5: ed8663754e56a03eedcd1ae7e5b92645
    SHA-256: a055fe46be759dae1e133164ee0b7e3d4bf98df73637d3ab454c558db1e5f027
    Size: 1.44 MB

Asianux Server 7 for x86_64
  1. mod_auth_mellon-0.14.0-2.el7.4.x86_64.rpm
    MD5: c470e569323815d883849bfeb6c11838
    SHA-256: 5fcecd0f10c1d9e9df0b81bd7190ff338491caa964666bfff223c5f541bd18c3
    Size: 1.25 MB