Information on source package simplesamlphp

Available versions

ReleaseVersion
wheezy1.9.2-1
wheezy (security)1.9.2-1+deb7u4
jessie1.13.1-2
jessie (security)1.13.1-2+deb8u1
stretch (security)1.14.11-1+deb9u1
buster1.15.4-1
sid1.15.4-1

Open issues

BugwheezyjessiestretchbustersidDescription
CVE-2018-7711fixedvulnerable (no DSA)vulnerable (no DSA)fixedfixedHTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 ...
CVE-2018-6520fixedvulnerable (no DSA)vulnerable (no DSA)fixedfixedSimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open ...
CVE-2017-12872fixedvulnerablevulnerablefixedfixedThe (1) Htpasswd authentication source in the authcrypt module and (2) ...
CVE-2017-12871fixedfixedvulnerablefixedfixedThe aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in ...
CVE-2017-12870vulnerable (no DSA, ignored)vulnerablevulnerablefixedfixedSimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle ...
CVE-2017-12868fixedvulnerablevulnerablefixedfixedThe secureCompare method in lib/SimpleSAML/Utils/Crypto.php in ...
CVE-2016-9955fixedvulnerable (no DSA)fixedfixedfixedThe SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before ...
CVE-2016-9814fixedvulnerable (no DSA)fixedfixedfixedThe validateSignature method in the SAML2\Utils class in SimpleSAMLphp ...

Open unimportant issues

BugwheezyjessiestretchbustersidDescription
CVE-2016-3124vulnerablevulnerablefixedfixedfixedThe sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote ...

Resolved issues

BugDescription
CVE-2018-7644The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp ...
CVE-2018-6521The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL ...
CVE-2018-6519The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 ...
CVE-2017-18122A signature-validation bypass issue was discovered in SimpleSAMLphp ...
CVE-2017-18121The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable ...
CVE-2017-12874The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof ...
CVE-2017-12873SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain ...
CVE-2017-12869The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows ...
CVE-2017-12867The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 ...
CVE-2012-0908Cross-site scripting (XSS) vulnerability in logout.php in ...
CVE-2012-0040Cross-site scripting (XSS) vulnerability in ...
CVE-2011-4625simplesamlphp xml encryption issues

Security announcements

DSA / DLADescription
DLA-1314-1simplesamlphp - security update
DSA-4127-1simplesamlphp - security update
DSA-4127-1simplesamlphp - security update
DLA-1298-1simplesamlphp - security update
DLA-1273-1simplesamlphp - security update
DLA-1205-1simplesamlphp - security update
DSA-2387-1simplesamlphp - cross site scripting
DSA-2330-1simplesamlphp - several

Search for package or bug name: Reporting problems