LWN.net Logo

simplesamlphp: xml encryption weakness

Package(s):simplesamlphp CVE #(s):
Created:October 27, 2011 Updated:November 2, 2011
Description: From the Debian advisory:

Issues were found in the handling of XML encryption in simpleSAMLphp, an application for federated authentication. The following two issues have been addressed:

It may be possible to use an SP as an oracle to decrypt encrypted messages sent to that SP.

It may be possible to use the SP as a key oracle which can be used to forge messages from that SP by issuing 300000-2000000 queries to the SP.

Alerts:
Debian DSA-2330-1 2011-10-27

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds