Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-9955

Опубликовано: 17 фев. 2017
Источник: ubuntu
Приоритет: medium
CVSS2: 4
CVSS3: 6.3

Описание

The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.

РелизСтатусПримечание
artful

not-affected

bionic

not-affected

cosmic

not-affected

devel

not-affected

disco

not-affected

eoan

not-affected

esm-apps/bionic

not-affected

esm-apps/focal

not-affected

esm-apps/jammy

not-affected

esm-apps/noble

not-affected

Показывать по

4 Medium

CVSS2

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
nvd
почти 9 лет назад

The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.

CVSS3: 6.3
debian
почти 9 лет назад

The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before ...

CVSS3: 6.3
github
около 6 лет назад

Incorrect signature verification in SimpleSAMLphp

4 Medium

CVSS2

6.3 Medium

CVSS3