CVE-2016-9814
published 2017-02-17CVE-2016-9814: The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and…
PriorityP341critical9.1CVSS 3.0
AVNACLPRNUINSUCNIHAH
EPSS
2.42%
82.3th percentile
The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cairographics | cairo | >= 0 < 1.14.6-1ubuntu0.1~esm1 | 1.14.6-1ubuntu0.1~esm1 |
| debian | simplesamlphp | < simplesamlphp 1.14.10-1 (bookworm) | simplesamlphp 1.14.10-1 (bookworm) |
| simplesamlphp | saml2 | <= 1.9 | — |
| simplesamlphp | saml2 | — | — |
| simplesamlphp | saml2 | — | — |
| simplesamlphp | saml2 | — | — |
| simplesamlphp | saml2 | — | — |
| simplesamlphp | saml2 | — | — |
| simplesamlphp | saml2 | — | — |
| simplesamlphp | saml2 | — | — |
| simplesamlphp | saml2 | — | — |
| simplesamlphp | saml2 | — | — |
| simplesamlphp | saml2 | — | — |
| simplesamlphp | saml2 | >= 0 < 1.8.1 | 1.8.1 |
| simplesamlphp | saml2 | >= 1.10 < 1.10.3 | 1.10.3 |
| simplesamlphp | saml2 | >= 1.9.0 < 1.9.1 | 1.9.1 |
| simplesamlphp | saml2 | >= 2.0 < 2.3.3 | 2.3.3 |
| simplesamlphp | simplesamlphp | <= 1.14.9 | — |
| simplesamlphp | simplesamlphp | — | — |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.10-1 | 1.14.10-1 |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.10-1 | 1.14.10-1 |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:L/Au:N/C:N/I:P/A:C
osv9.1CRITICAL
vendor_debian9.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
SimpleSAMLphp SAML2 spoof SAML responses
osv·2022-05-14
CVE-2016-9814 [CRITICAL] SimpleSAMLphp SAML2 spoof SAML responses
SimpleSAMLphp SAML2 spoof SAML responses
The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
GHSA
SimpleSAMLphp SAML2 spoof SAML responses
ghsa·2022-05-14
CVE-2016-9814 [CRITICAL] SimpleSAMLphp SAML2 spoof SAML responses
SimpleSAMLphp SAML2 spoof SAML responses
The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
OSV
cairo vulnerabilities
osv·2022-05-10·CVSS 5.5
CVE-2016-9082 cairo vulnerabilities
cairo vulnerabilities
Gustavo Grieco, Alberto Garcia, Francisco Oca, Suleman Ali, and others
discovered that Cairo incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2016-9082, CVE-2017-9814, CVE-2019-6462)
Stephan Bergmann discovered that Cairo incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service,
or possibly execute arbitrary code.
(CVE-2020-35492)
OSV
CVE-2016-9814: The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1
osv·2017-02-17·CVSS 9.1
CVE-2016-9814 [CRITICAL] CVE-2016-9814: The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1
The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
Debian
CVE-2016-9814: simplesamlphp - The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1....
vendor_debian·2016·CVSS 9.1
CVE-2016-9814 [CRITICAL] CVE-2016-9814: simplesamlphp - The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1....
The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
Scope: local
bookworm: resolved (fixed in 1.14.10-1)
bullseye: resolved (fixed in 1.14.10-1)
sid: resolved (fixed in 1.14.10-1)
No detection rules found.
No public exploits indexed.
2017-02-17
Published