Information on source package simplesamlphp

Available versions

ReleaseVersion
jessie1.13.1-2+deb8u1
jessie (security)1.13.1-2+deb8u2
stretch (security)1.14.11-1+deb9u1
buster1.16.3-1
sid1.17.2-2

Open issues

BugjessiestretchbustersidDescription
CVE-2018-7711vulnerable (no DSA)vulnerable (no DSA)fixedfixedHTTPRedirect.php in the saml2 library in SimpleSAMLphp before 1.15.4 h ...
CVE-2018-6520vulnerable (no DSA)vulnerable (no DSA)fixedfixedSimpleSAMLphp before 1.15.2 allows remote attackers to bypass an open ...
CVE-2017-12872fixedvulnerable (no DSA)fixedfixedThe (1) Htpasswd authentication source in the authcrypt module and (2) ...
CVE-2017-12871fixedvulnerablefixedfixedThe aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAML ...
CVE-2017-12870vulnerable (no DSA, ignored)vulnerablefixedfixedSimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle ...
CVE-2016-9955vulnerable (no DSA)fixedfixedfixedThe SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before ...
CVE-2016-9814vulnerable (no DSA)fixedfixedfixedThe validateSignature method in the SAML2\Utils class in SimpleSAMLphp ...

Open unimportant issues

BugjessiestretchbustersidDescription
CVE-2016-3124vulnerablefixedfixedfixedThe sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote at ...

Resolved issues

BugDescription
CVE-2018-7644The XmlSecLibs library as used in the saml2 library in SimpleSAMLphp b ...
CVE-2018-6521The sqlauth module in SimpleSAMLphp before 1.15.2 relies on the MySQL ...
CVE-2018-6519The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1. ...
CVE-2017-18122A signature-validation bypass issue was discovered in SimpleSAMLphp th ...
CVE-2017-18121The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable ...
CVE-2017-12874The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XM ...
CVE-2017-12873SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain se ...
CVE-2017-12869The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remot ...
CVE-2017-12868The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleS ...
CVE-2017-12867The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 an ...
CVE-2012-0908Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLph ...
CVE-2012-0040Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie ...
CVE-2011-4625simplesamlphp xml encryption issues

Security announcements

DSA / DLADescription
DLA-1408-1simplesamlphp - security update
DLA-1314-1simplesamlphp - security update
DSA-4127-1simplesamlphp - security update
DSA-4127-1simplesamlphp - security update
DLA-1298-1simplesamlphp - security update
DLA-1273-1simplesamlphp - security update
DLA-1205-1simplesamlphp - security update
DSA-2387-1simplesamlphp - cross site scripting
DSA-2330-1simplesamlphp - several

Search for package or bug name: Reporting problems