DSA-2330-1 simplesamlphp -- xml encryption weaknessID: oval:org.secpod.oval:def:600642 | Date: (C)2012-01-30 (M)2022-10-10 |
Class: PATCH | Family: unix |
Issues were found in the handling of XML encryption in simpleSAMLphp, an application for federated authentication. The following two issues have been addressed: It may be possible to use an SP as an oracle to decrypt encrypted messages sent to that SP. It may be possible to use the SP as a key oracle which can be used to forge messages from that SP by issuing 300000-2000000 queries to the SP. The oldstable distribution does not contain simplesamlphp.