USN-4597-1
Dashboard / Vulnerabilities / USN-4597-1
USN-4597-1
Summary: libapache2-mod-auth-mellon vulnerabilities
Details: François Kooman discovered that mod_auth_mellon incorrectly handled cookies. An attacker could possibly use this issue to cause a Cross-Site Session Transfer attack. (CVE-2017-6807) It was discovered that mod_auth_mellon incorrectly handled certain requests. An attacker could possibly use this issue to redirect a user to a malicious URL. (CVE-2019-3877) It was discovered that mod_auth_mellon incorrectly handled certain requests. An attacker could possibly use this issue to access sensitive information. (CVE-2019-3878)
References: https://ubuntu.com/security/notices/USN-4597-1, https://ubuntu.com/security/CVE-2017-6807, https://ubuntu.com/security/CVE-2019-3877, https://ubuntu.com/security/CVE-2019-3878
Affected packages
Package
Name: libapache2-mod-auth-mellon
Purl: pkg:deb/ubuntu/[email protected]+deb9u1build0.16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
