Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-12872

Опубликовано: 01 сент. 2017
Источник: debian

Описание

The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
simplesamlphpfixed1.14.15-1package
simplesamlphpno-dsastretchpackage

Примечания

  • https://simplesamlphp.org/security/201703-01

  • Patches: https://github.com/simplesamlphp/simplesamlphp/commit/ab7761d4a523a4ed00479fb1ddba688e7ca72439

  • https://github.com/simplesamlphp/simplesamlphp/commit/caf764cc2c9b68ac29741070ebdf133a595443f1

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 8 лет назад

The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.

CVSS3: 5.9
nvd
больше 8 лет назад

The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.

CVSS3: 5.9
github
больше 3 лет назад

SimpleSAMLphp allows timing side-channel attacks