[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248585

 
 

909

 
 

195621

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2017-12868 -- simplesamlphp

ID: oval:org.secpod.oval:def:1901679Date: (C)2019-03-22   (M)2023-12-20
Class: VULNERABILITYFamily: unix




The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

Platform:
Ubuntu 16.04
Ubuntu 14.04
Product:
simplesamlphp
Reference:
CVE-2017-12868
CVE    1
CVE-2017-12868
CPE    3
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/o:ubuntu:ubuntu_linux:14.04
cpe:/a:simplesamlphp:simplesamlphp

© SecPod Technologies