Candidate: CVE-2010-2450 PublicDate: 2019-11-07 21:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2450 Description: The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=571631 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_shibboleth-sp2: upstream_shibboleth-sp2: released (2.3.1+dfsg-2) hardy_shibboleth-sp2: DNE lucid_shibboleth-sp2: ignored (reached end-of-life) maverick_shibboleth-sp2: not-affected (2.3.1+dfsg-2) natty_shibboleth-sp2: not-affected oneiric_shibboleth-sp2: not-affected precise_shibboleth-sp2: not-affected quantal_shibboleth-sp2: not-affected raring_shibboleth-sp2: not-affected saucy_shibboleth-sp2: not-affected devel_shibboleth-sp2: not-affected Patches_shibboleth-sp: upstream_shibboleth-sp: needs-triage hardy_shibboleth-sp: ignored (code not present) lucid_shibboleth-sp: DNE maverick_shibboleth-sp: DNE natty_shibboleth-sp: DNE oneiric_shibboleth-sp: DNE precise_shibboleth-sp: DNE quantal_shibboleth-sp: DNE raring_shibboleth-sp: DNE saucy_shibboleth-sp: DNE devel_shibboleth-sp: DNE