-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2019.1599
                Important: mod_auth_mellon security update
                                7 May 2019

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           mod_auth_mellon
Publisher:         Red Hat
Operating System:  Red Hat Enterprise Linux Server 8
Impact/Access:     Unauthorised Access -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2019-3878  

Reference:         ESB-2019.1316
                   ESB-2019.1256
                   ESB-2019.1049
                   ESB-2019.0965.2

Original Bulletin: 
   https://access.redhat.com/errata/RHSA-2019:0985

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Important: mod_auth_mellon security update
Advisory ID:       RHSA-2019:0985-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2019:0985
Issue date:        2019-05-07
CVE Names:         CVE-2019-3878 
=====================================================================

1. Summary:

An update for mod_auth_mellon is now available for Red Hat Enterprise Linux
8.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64

3. Description:

The mod_auth_mellon module for the Apache HTTP Server is an authentication
service that implements the SAML 2.0 federation protocol. The module grants
access based on the attributes received in assertions generated by an IdP
server.

Security Fix(es):

* mod_auth_mellon: authentication bypass in ECP flow (CVE-2019-3878)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1691126 - CVE-2019-3878 mod_auth_mellon: authentication bypass in ECP flow

6. Package List:

Red Hat Enterprise Linux AppStream (v. 8):

Source:
mod_auth_mellon-0.14.0-3.el8_0.2.src.rpm

aarch64:
mod_auth_mellon-0.14.0-3.el8_0.2.aarch64.rpm
mod_auth_mellon-debuginfo-0.14.0-3.el8_0.2.aarch64.rpm
mod_auth_mellon-debugsource-0.14.0-3.el8_0.2.aarch64.rpm
mod_auth_mellon-diagnostics-debuginfo-0.14.0-3.el8_0.2.aarch64.rpm

ppc64le:
mod_auth_mellon-0.14.0-3.el8_0.2.ppc64le.rpm
mod_auth_mellon-debuginfo-0.14.0-3.el8_0.2.ppc64le.rpm
mod_auth_mellon-debugsource-0.14.0-3.el8_0.2.ppc64le.rpm
mod_auth_mellon-diagnostics-debuginfo-0.14.0-3.el8_0.2.ppc64le.rpm

s390x:
mod_auth_mellon-0.14.0-3.el8_0.2.s390x.rpm
mod_auth_mellon-debuginfo-0.14.0-3.el8_0.2.s390x.rpm
mod_auth_mellon-debugsource-0.14.0-3.el8_0.2.s390x.rpm
mod_auth_mellon-diagnostics-debuginfo-0.14.0-3.el8_0.2.s390x.rpm

x86_64:
mod_auth_mellon-0.14.0-3.el8_0.2.x86_64.rpm
mod_auth_mellon-debuginfo-0.14.0-3.el8_0.2.x86_64.rpm
mod_auth_mellon-debugsource-0.14.0-3.el8_0.2.x86_64.rpm
mod_auth_mellon-diagnostics-debuginfo-0.14.0-3.el8_0.2.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2019-3878
https://access.redhat.com/security/updates/classification/#important

8. Contact:

The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2019 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBXNEIV9zjgjWX9erEAQgPZhAAhhwkxDBonflrJVmbccp1nXjvW3tGRnud
ghXrKfgzIa8AY6lH+pEKs+pG8G3FWWDr6enQCHjXx/9rnbi6jtw0YJir81Aa9S31
U32hYVa3NzE7wVZ9ZEC2SMRftGnDfeQ6/k18uHBBBKCZjda5knEw4hJ+9vWhTAsR
viUYZ9gLBEGw7ipfyHvMTmLvIm6A2wc8QALUZidZOh7rYZ/o8Om4DBw2641HSMyj
ArqATPfP9q4r5MNPTfhGIbiT+agg1/UiDZKWtr/4Pm8GYhLQ+UfmhbbY8zc8WIks
Z7ProZmpICuZ/mL93k1rroYcJ6yVcJxwq1+fQy0GboBZYi478DK1MZHgGdUOwwyY
0NJDiJbe+5RqAKgLodcLN8Wi1iUXA7ofUwF4toPt68697zc7K+BjX3mqo0CAxhgh
ivWGfFbaliM8l3piYt9EboR8VybGHh7Od9vkP2jlOtDieMa60WTfdIUz2Q37Uo3v
waMLtqQIwCO+0KSag99PEyg6TSXBO+/Vne3RogDnVqsE1XS90c/WtYnp3FZ8dmui
rrTqQRYLZEjlwLX4Z2N/fs+Hj8Rr5A9JdI9mZXZbII8YOipjvQJRCyWPytf7ME+O
fUIR3dtB7hpkJOS+cNtvO/mXXLxeOlfzxGiVwcoBT8635y/zv8yKZcEuVmReB/Lt
+TJi0IvHsPI=
=kyCl
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXNEkymaOgq3Tt24GAQjKfg/+Od5jS7/W1IXfGDO16HWb5Oc2RnaF58LI
hlklwH8BDkNHEDbNVc1Ux3Whntqc8tXnF7qZMu5Nj5zmyAEG9tuuCYbIz04Lzrsg
GT6eiv9O3rqQmeKeVGBf1s1NIy6OYhhGy8XC9PWqlGtBI5M0tywbsX0nqEEyh4Vl
tnneIev1rPYGaxEJZQgSSkTuDUBhbVA6TQ43I7e75t03LIYcOc2lrdR7Vvhoxg7Q
T8ESklhqi8vNmTN8uYe/Ebn//Te5XGmkjW7P9c989oAWF1Rp0Yt5iYrteBxTWaae
7M/KUZRAqQ6TcY0YgQ6XNV6m3ecE/OJJbTeiP9LB3mznjaT+HdYV+7Qt/OmL+p9W
Hp5qEnFzpfLCCoaoDvWz4BufOMgPFg55ri1CIxftpN+NR1g5BzwAqY6YqUcy8II8
9OkLHdcno54riKZ9ghecqi6R7DG3SZvQP5UH5NMJBLvRLQX1IDr+Ug2aqIpwUTXc
tlG+IXi3ShfCKBlK5m1WDzkkZ/BRtLb8yvLeHGTJ87Pqd9Nv56U/P/DZI7D842Tb
K2vqM322mvSh0244nSiVtHjgekdqEwPenQF/VtgHtYi/OCwUliip7wndK8N4IEzw
hwHe2b1druf3Il6Woh7dkY+Uby66yi0pR6AXRlBtt/ff0nO/+XdBXsSKtNXk+tjW
GMi/APg+i6I=
=Wmuk
-----END PGP SIGNATURE-----