oss-sec mailing list archives

CVE Request: SimpleSAMLphp: SSPSA 201612-02: Incorrect signature verification


From: Salvatore Bonaccorso <carnil () debian org>
Date: Wed, 14 Dec 2016 15:48:22 +0100

Hi

SimpleSAMLphp has released (another) update fixing an incorrect
signature verification issue (different from SSPSA 201612-01 /
CVE-2016-9814). It affects versions of SimpeSAMLphp before 1.14.11.

Upstream advisory: https://simplesamlphp.org/security/201612-02

References:
https://github.com/simplesamlphp/simplesamlphp/commit/a2326d75dd14accaac162dd2cb30aaefcc1f9205

Could you please assign a CVE for this issue?

Regards,
Salvatore


Current thread: