CVE-2017-12872
published 2017-09-01CVE-2017-12872: The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to…
PriorityP431medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
1.45%
70.3th percentile
The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | simplesamlphp | < simplesamlphp 1.14.15-1 (bookworm) | simplesamlphp 1.14.15-1 (bookworm) |
| simplesamlphp | simplesamlphp | <= 1.14.11 | — |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.15-1 | 1.14.15-1 |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.15-1 | 1.14.15-1 |
| simplesamlphp | simplesamlphp | >= 0 < 1.15.0-rc1 | 1.15.0-rc1 |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-12872: simplesamlphp - The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAM...
vendor_debian·2017·CVSS 5.9
CVE-2017-12872 [MEDIUM] CVE-2017-12872: simplesamlphp - The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAM...
The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.
Scope: local
bookworm: resolved (fixed in 1.14.15-1)
bullseye: resolved (fixed in 1.14.15-1)
sid: resolved (fixed in 1.14.15-1)
GHSA
SimpleSAMLphp allows timing side-channel attacks
ghsa·2022-05-14
CVE-2017-12872 [MEDIUM] CWE-200 SimpleSAMLphp allows timing side-channel attacks
SimpleSAMLphp allows timing side-channel attacks
The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.
OSV
SimpleSAMLphp allows timing side-channel attacks
osv·2022-05-14
CVE-2017-12872 [MEDIUM] SimpleSAMLphp allows timing side-channel attacks
SimpleSAMLphp allows timing side-channel attacks
The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.
OSV
CVE-2017-12872: The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1
osv·2017-09-01·CVSS 5.9
CVE-2017-12872 [MEDIUM] CVE-2017-12872: The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1
The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2017/12/msg00007.htmlhttps://lists.debian.org/debian-lts-announce/2018/06/msg00017.htmlhttps://simplesamlphp.org/security/201703-01https://lists.debian.org/debian-lts-announce/2017/12/msg00007.htmlhttps://lists.debian.org/debian-lts-announce/2018/06/msg00017.htmlhttps://simplesamlphp.org/security/201703-01
2017-09-01
Published