Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12868

Опубликовано: 01 сент. 2017
Источник: debian
EPSS Низкий

Описание

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
simplesamlphpfixed1.14.15-1package
simplesamlphpnot-affectedstretchpackage

Примечания

  • https://simplesamlphp.org/security/201705-01

  • Patch: https://github.com/simplesamlphp/simplesamlphp/commit/caf764cc2c9b68ac29741070ebdf133a595443f1

EPSS

Процентиль: 72%
0.00764
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
nvd
почти 8 лет назад

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
github
около 3 лет назад

SimpleSAMLphp Session fixation issue and authentication bypass in the authcrypt module

EPSS

Процентиль: 72%
0.00764
Низкий