simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.
The product does not handle or incorrectly handles an exceptional condition.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Simplesamlphp | Simplesamlphp | 1.6.0 (including) | 1.6.3 (excluding) |
Simplesamlphp | Simplesamlphp | 1.8.0 (including) | 1.8.2 (excluding) |
Simplesamlphp | Ubuntu | devel | * |
Simplesamlphp | Ubuntu | maverick | * |
Simplesamlphp | Ubuntu | natty | * |
Simplesamlphp | Ubuntu | oneiric | * |
Simplesamlphp | Ubuntu | precise | * |
Simplesamlphp | Ubuntu | quantal | * |
Simplesamlphp | Ubuntu | raring | * |
Simplesamlphp | Ubuntu | upstream | * |