USN-4291-1: mod-auth-mellon vulnerability

24 February 2020

libapache2-mod-auth-mellon vulnerability

Packages

  • libapache2-mod-auth-mellon - SAML 2.0 authentication module for Apache

Details

It was discovered that mod_auth_mellon incorrectly handled certain
requests. An attacker could possibly use this issue to redirect a user to a
malicious URL.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 19.10
Ubuntu 18.04

In general, a standard system update will make all the necessary changes.

References