cbcvebase.
CVE-2017-12874
published 2017-09-01

CVE-2017-12874: The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation…

high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiansimplesamlphp< simplesamlphp 1.14.11-1 (bookworm)simplesamlphp 1.14.11-1 (bookworm)
simplesamlphpinfocard_module
simplesamlphpsimplesamlphp>= 0 < 1.14.11-11.14.11-1
simplesamlphpsimplesamlphp>= 0 < 1.14.11-11.14.11-1
simplesamlphpsimplesamlphp-module-infocard>= 0 < 1.0.11.0.1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH