Описание
SimpleSAMLphp InfoCard module Incorrect signature verification
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2017-12874
- https://github.com/simplesamlphp/simplesamlphp-module-infocard/commit/63b84cc837ea62bf87f4bf4af29b4420f49311a9
- https://github.com/FriendsOfPHP/security-advisories/blob/master/simplesamlphp/simplesamlphp-module-infocard/CVE-2017-12874.yaml
- https://lists.debian.org/debian-lts-announce/2017/12/msg00007.html
- https://simplesamlphp.org/security/201612-03
- https://www.debian.org/security/2018/dsa-4127
Пакеты
Наименование
simplesamlphp/simplesamlphp-module-infocard
composer
Затронутые версииВерсия исправления
< 1.0.1
1.0.1
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 8 лет назад
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
CVSS3: 7.5
nvd
больше 8 лет назад
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
CVSS3: 7.5
debian
больше 8 лет назад
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XM ...