CVE-2017-2646
published 2018-07-27CVE-2017-2646: It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse() method…
PriorityP336high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.85%
76.8th percentile
It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in a infinite loop. An attacker could use this flaw to conduct denial of service attacks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | keycloak | — | — |
| redhat | keycloak | < 2.5.5 | 2.5.5 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
keycloak: DoS via SAML request
vendor_redhat·2017-03-10·CVSS 7.5
CVE-2017-2646 [HIGH] CWE-835 keycloak: DoS via SAML request
keycloak: DoS via SAML request
It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in a infinite loop. An attacker could use this flaw to conduct denial of service attacks.
Package: rh-sso7-keycloak (Red Hat Single Sign-On 7) - Not affected
OSV
Keycloak vulnerable to infinite loop based Denial of Service
osv·2018-10-18
CVE-2017-2646 [HIGH] Keycloak vulnerable to infinite loop based Denial of Service
Keycloak vulnerable to infinite loop based Denial of Service
When Keycloak versions prior to 2.5.5 receive a Logout request with an Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in an infinite loop. An attacker could use this flaw to conduct denial of service attacks.
GHSA
Keycloak vulnerable to infinite loop based Denial of Service
ghsa·2018-10-18
CVE-2017-2646 [HIGH] CWE-835 Keycloak vulnerable to infinite loop based Denial of Service
Keycloak vulnerable to infinite loop based Denial of Service
When Keycloak versions prior to 2.5.5 receive a Logout request with an Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in an infinite loop. An attacker could use this flaw to conduct denial of service attacks.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7599 libtiff: Unsigned short out of range in tif_dirwrite.c
bugzilla·2017-04-11·CVSS 7.8
CVE-2017-7599 [HIGH] CVE-2017-7599 libtiff: Unsigned short out of range in tif_dirwrite.c
CVE-2017-7599 libtiff: Unsigned short out of range in tif_dirwrite.c
LibTIFF has an "outside the range of representable values of type short" undefined behavior issue, which might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
Upstream bug:
http://bugzilla.maptools.org/show_bug.cgi?id=2646
Upstream patch:
https://github.com/vadz/libtiff/commit/3144e57770c1e4d26520d8abee750f8ac8b75490
Discussion:
Created mingw-libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1438465]
---
Created mingw-libtiff tracking bugs for this issue:
Affects: epel-7 [bug 1438466]
---
Created libtiff tracking bugs for this issue:
Affects: fedora-all [bug 1441273]
Bugzilla
CVE-2017-2646 keycloak: DoS via SAML request
bugzilla·2017-03-10·CVSS 7.5
CVE-2017-2646 [HIGH] CVE-2017-2646 keycloak: DoS via SAML request
CVE-2017-2646 keycloak: DoS via SAML request
It was found that a logout request containing extension element will trigger an infinite loop. An attacker could use this flaw to conduct denial of service attacks.
Discussion:
No Red Hat products are affected by this flaw.
2018-07-27
Published