ZeroHour
Ubuntu Security Noticespublished ()ingested

USN-8768-1: Shibboleth vulnerability

mediumAdvisoryimportance 15
AI summary · glm-5.3

Ubuntu patches Shibboleth SQL injection in the ODBC storage plugin allowing remote attackers to extract sensitive information.

Ubuntu security notice USN-8768-1 fixes a Shibboleth vulnerability discovered by Florian Stuhlmann. The software incorrectly escaped input when using the ODBC storage plugin, allowing a remote attacker to perform SQL injection attacks and obtain sensitive information. Users are advised to update the Shibboleth package.

  • Improper input escaping in ODBC storage plugin enables SQL injection
  • Remote attackers could read sensitive database information
Full article

Florian Stuhlmann discovered that Shibboleth incorrectly escaped input when using the ODBC storage plugin. A remote attacker could possibly use this issue to perform SQL injection attacks and obtain sensitive information.

This source does not provide full text. Read it at ubuntu.com.