Vulnerability Description
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simplesamlphp | Infocard Module | 1.0 |
| Debian | Debian Linux | 7.0 |
Related Weaknesses (CWE)
References
- https://lists.debian.org/debian-lts-announce/2017/12/msg00007.htmlMailing ListThird Party Advisory
- https://simplesamlphp.org/security/201612-03PatchVendor Advisory
- https://www.debian.org/security/2018/dsa-4127Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2017/12/msg00007.htmlMailing ListThird Party Advisory
- https://simplesamlphp.org/security/201612-03PatchVendor Advisory
- https://www.debian.org/security/2018/dsa-4127Third Party Advisory
FAQ
What is CVE-2017-12874?
CVE-2017-12874 is a vulnerability with a CVSS score of 7.5 (HIGH). The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
How severe is CVE-2017-12874?
CVE-2017-12874 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-12874?
Check the references section above for vendor advisories and patch information. Affected products include: Simplesamlphp Infocard Module, Debian Debian Linux.