CVE Vulnerabilities

CVE-2011-4625

Improper Handling of Exceptional Conditions

Published: Nov 06, 2019 | Modified: Aug 18, 2020
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Simplesamlphp Simplesamlphp 1.6.0 (including) 1.6.3 (excluding)
Simplesamlphp Simplesamlphp 1.8.0 (including) 1.8.2 (excluding)
Simplesamlphp Ubuntu devel *
Simplesamlphp Ubuntu maverick *
Simplesamlphp Ubuntu natty *
Simplesamlphp Ubuntu oneiric *
Simplesamlphp Ubuntu precise *
Simplesamlphp Ubuntu quantal *
Simplesamlphp Ubuntu raring *
Simplesamlphp Ubuntu upstream *

References