← Voltar para CVEs
CVE-2017-12868
N/ADescricao
The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado9/1/2017
Ultima modificacao4/20/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
php:phpsimplesamlphp:simplesamlphp
Fraquezas (CWE)
CWE-384
Referencias
https://github.com/simplesamlphp/simplesamlphp/commit/4bc629658e7b7d17c9ac3fe0da7dc5df71f1b85e(cve@mitre.org)
https://simplesamlphp.org/security/201705-01(cve@mitre.org)
https://github.com/simplesamlphp/simplesamlphp/commit/4bc629658e7b7d17c9ac3fe0da7dc5df71f1b85e(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2017/12/msg00007.html(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2018/06/msg00017.html(af854a3a-2127-422b-91ae-364da2661108)
https://simplesamlphp.org/security/201705-01(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.