Vulnerability Description
A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apereo | Phpcas | 1.2.2 |
| Linux | Linux Kernel | - |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2012/03/05/7Mailing ListThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1104Issue TrackingThird Party Advisory
- https://gitlab.vsb.cz/kal0178/sixmon/blob/b18bcde090dc38fc968a0b1e38d1dab08b8c36Release NotesThird Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2012-1104Third Party Advisory
- https://www.securityfocus.com/bid/52279Third Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2012/03/05/7Mailing ListThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-1104Issue TrackingThird Party Advisory
- https://gitlab.vsb.cz/kal0178/sixmon/blob/b18bcde090dc38fc968a0b1e38d1dab08b8c36Release NotesThird Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2012-1104Third Party Advisory
- https://www.securityfocus.com/bid/52279Third Party AdvisoryVDB Entry
FAQ
What is CVE-2012-1104?
CVE-2012-1104 is a vulnerability with a CVSS score of 5.3 (MEDIUM). A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.
How severe is CVE-2012-1104?
CVE-2012-1104 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-1104?
Check the references section above for vendor advisories and patch information. Affected products include: Apereo Phpcas, Linux Linux Kernel, Debian Debian Linux.