CVE-2017-12868
Summary
| CVE | CVE-2017-12868 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-01 13:29:00 UTC |
| Updated | 2018-07-01 01:29:00 UTC |
| Description | The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation. |
Risk And Classification
Problem Types: CWE-384
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Php | Php | All | All | All | All |
| Application | Php | Php | All | All | All | All |
| Application | Simplesamlphp | Simplesamlphp | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| bugfix: SimpleSAML\Utils\Crypto returns true for different strings us… · simplesamlphp/simplesamlphp@4bc6296 · GitHub | CONFIRM | github.com | Issue Tracking, Patch, Third Party Advisory |
| [SECURITY] [DLA 1408-1] simplesamlphp security update | MLIST | lists.debian.org | |
| [SECURITY] [DLA 1205-1] simplesamlphp security update | MLIST | lists.debian.org | |
| SimpleSAMLphp | CONFIRM | simplesamlphp.org | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.