CVE-2010-2450
published 2019-11-07CVE-2010-2450: The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.20%
65.1th percentile
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | shibboleth-sp | — | — |
| shibboleth | service_provider | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2010-2450: shibboleth-sp - The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth ...
vendor_debian·2010·CVSS 7.5
CVE-2010-2450 [HIGH] CVE-2010-2450: shibboleth-sp - The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth ...
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-9cvv-j545-66mj: The keygen
ghsa_unreviewed·2022-04-21
CVE-2010-2450 [MEDIUM] GHSA-9cvv-j545-66mj: The keygen
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=571631https://security-tracker.debian.org/tracker/CVE-2010-2450https://todos.internet2.edu/browse/SSPCPP-106https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=571631https://security-tracker.debian.org/tracker/CVE-2010-2450https://todos.internet2.edu/browse/SSPCPP-106
2019-11-07
Published