CVE Vulnerabilities

CVE-2011-4625

Improper Handling of Exceptional Conditions

Published: Nov 06, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

NameVendorStart VersionEnd Version
SimplesamlphpSimplesamlphp1.6.0 (including)1.6.3 (excluding)
SimplesamlphpSimplesamlphp1.8.0 (including)1.8.2 (excluding)
SimplesamlphpUbuntudevel*
SimplesamlphpUbuntumaverick*
SimplesamlphpUbuntunatty*
SimplesamlphpUbuntuoneiric*
SimplesamlphpUbuntuprecise*
SimplesamlphpUbuntuquantal*
SimplesamlphpUbunturaring*
SimplesamlphpUbuntuupstream*

References