[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

251139

 
 

909

 
 

196159

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2017-12871 -- simplesamlphp

ID: oval:org.secpod.oval:def:2000848Date: (C)2019-06-03   (M)2021-09-11
Class: VULNERABILITYFamily: unix




The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector .

Platform:
Debian 9.x
Product:
simplesamlphp
Reference:
CVE-2017-12871
CVE    1
CVE-2017-12871
CPE    2
cpe:/o:debian:debian_linux:9.x
cpe:/a:simplesamlphp:simplesamlphp

© SecPod Technologies