VYPR

rpm package

opensuse/shibboleth-sp&distro=openSUSE Leap 15.1

pkg:rpm/opensuse/shibboleth-sp&distro=openSUSE%20Leap%2015.1

Vulnerabilities (1)

  • CVE-2019-19191Nov 21, 2019
    affected < 2.6.1-lp151.3.3.1fixed 2.6.1-lp151.3.3.1

    Shibboleth Service Provider (SP) 3.x before 3.1.0 shipped a spec file that calls chown on files in a directory controlled by the service user (the shibd account) after installation. This allows the user to escalate to root by pointing symlinks to files such as /etc/shadow.