[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[upki-fed:00950] Shibboleth SP の脆弱性について (2015/7/21)



$B3XG'>pJs8r49(BML$B;22CpJs3X8&5f=j!!3XG';vL36I$G$9!#(B
$BJ?AG$h$j3XG'$N1?1D$K$46(NO$r;r$j!$$"$j$,$H$&$4$6$$$^$9!#(B


Shibboleth Project$B$h$j(BShibboleth SP$B$K4X$9$k@HZ$N%f!<%6$K(B
$B$h$k(BDoS$B967b$rl9g!$K\@H$C$F(BSP$B$r9=C[$7$?>l9g!$(BOS$B$O(BCentOS$B$N(B5$B7O$^$?$O(B6$B7O$H$J$j(B
$B$^$9!#$3$l$i$N(BOS$B$N>l9g$K$O!$(BShibboleth SP$B$r%j%]%8%H%jDs6!$N:G?7HG$K%"%C(B
$B%W%G!<%H$7$F$$$?$@$/$3$H$GBP=h$,40N;$7$^$9!#(B

$B"((B $B0MB8%Q%C%1!<%8$H$7$F!$(BOpenSAML-C$B$H(BXMLTooling-C$B$b:G?7%P!<%8%g%s$K%"%C(B
   $B%W%G!<%H$5$l$^$9!#(B

$B$=$NB>4D6-$G$NBP=h$K$D$$$F$O!$%;%-%e%j%F%#%"%I%P%$%6%j(B[1]$B$r$4;2>H$/$@(B
$B$5$$!#(B

$B$J$*!$$9$0$K(BSP$B$r%"%C%W%G!<%H$9$k$3$H$,:$Fq$J>l9g$K$O!$%a%?%G!<%?$d(BSAML$BDL(B
$B?.$G(BSchema$B$N@09g%A%'%C%/(B(Schema Validation)$B$r6/@)$9$k$3$H$K$h$j!$@Hl(B
$B9g$K$O!$LdBj$rG'<1$7$?>e$GH$/$@$5$$!#(B

[1] Shibboleth Service Provider Security Advisory [21 July 2015]
    https://shibboleth.net/community/advisories/secadv_20150721.txt



-- 
=========================================================
$B!!9qN)>pJs3X8&5f=j(B $B3X=Q4pHW2](B $B3XG';vL36I!!!JC4Ev!'LnED!K(B
$B!!(BTEL$B!'(B03-4212-2218$B!!(xxxxxxxxxxxxxxx@xxxxxxxxx
$B!!3XG'(BWeb$B%Z!<%8(B  https://www.gakunin.jp/
$B!!?=@A%7%9%F%`(B   https://office.gakunin.nii.ac.jp/
=========================================================