Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-6519

Опубликовано: 02 фев. 2018
Источник: debian
EPSS Низкий

Описание

The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
simplesamlphpfixed1.15.2-1package
simplesamlphpnot-affectedwheezypackage

Примечания

  • minor issue

  • https://simplesamlphp.org/security/201801-01

  • The issue lies in the simplesamlphp/saml2 part, which is

  • updated in 1.15.2 to the respective fixed version.

  • https://github.com/simplesamlphp/saml2/commit/726404bf7b4085a9eb9c9a869af1ecc146bd8f6d

EPSS

Процентиль: 64%
0.00467
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.

CVSS3: 7.5
nvd
около 8 лет назад

The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for fraction-of-seconds data in a timestamp.

CVSS3: 7.5
github
больше 3 лет назад

SimpleSAMLphp SAML2 library Regular Expression Denial of Service vulnerability

EPSS

Процентиль: 64%
0.00467
Низкий