CVE-2017-12873

NameCVE-2017-12873
DescriptionSimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
simplesamlphp (PTS)wheezy1.9.2-1vulnerable
jessie1.13.1-2vulnerable
stretch1.14.11-1vulnerable
buster, sid1.14.15-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
simplesamlphpsource(unstable)1.14.15-1high

Notes

https://simplesamlphp.org/security/201612-04

Search for package or bug name: Reporting problems