CVE-2017-12874
published 2017-09-01CVE-2017-12874: The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation…
PriorityP434high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
1.26%
66.2th percentile
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | simplesamlphp | < simplesamlphp 1.14.11-1 (bookworm) | simplesamlphp 1.14.11-1 (bookworm) |
| simplesamlphp | infocard_module | — | — |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.11-1 | 1.14.11-1 |
| simplesamlphp | simplesamlphp | >= 0 < 1.14.11-1 | 1.14.11-1 |
| simplesamlphp | simplesamlphp-module-infocard | >= 0 < 1.0.1 | 1.0.1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-12874: simplesamlphp - The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages...
vendor_debian·2017·CVSS 7.5
CVE-2017-12874 [HIGH] CVE-2017-12874: simplesamlphp - The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages...
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
Scope: local
bookworm: resolved (fixed in 1.14.11-1)
bullseye: resolved (fixed in 1.14.11-1)
sid: resolved (fixed in 1.14.11-1)
GHSA
SimpleSAMLphp InfoCard module Incorrect signature verification
ghsa·2022-05-14
CVE-2017-12874 [HIGH] CWE-20 SimpleSAMLphp InfoCard module Incorrect signature verification
SimpleSAMLphp InfoCard module Incorrect signature verification
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
OSV
SimpleSAMLphp InfoCard module Incorrect signature verification
osv·2022-05-14
CVE-2017-12874 [HIGH] SimpleSAMLphp InfoCard module Incorrect signature verification
SimpleSAMLphp InfoCard module Incorrect signature verification
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
OSV
CVE-2017-12874: The InfoCard module 1
osv·2017-09-01·CVSS 7.5
CVE-2017-12874 [HIGH] CVE-2017-12874: The InfoCard module 1
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2017/12/msg00007.htmlhttps://simplesamlphp.org/security/201612-03https://www.debian.org/security/2018/dsa-4127https://lists.debian.org/debian-lts-announce/2017/12/msg00007.htmlhttps://simplesamlphp.org/security/201612-03https://www.debian.org/security/2018/dsa-4127
2017-09-01
Published