Package        : simplesamlphp
Version        : 1.9.2-1+deb7u4
CVE ID         : CVE-2018-7711

Cure53 discovered that in SimpleSAMLphp, in rare circumstances an
invalid signature on the SAML 2.0 HTTP Redirect binding could be
considered valid.

Additionally this update fixes a regression introduced in DLA-1298
by the backported patch for SSA-201802-01/CVE-2018-7644.

For Debian 7 "Wheezy", these problems have been fixed in version
1.9.2-1+deb7u4.

We recommend that you upgrade your simplesamlphp packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Debian LTS: DLA-1314-1: simplesamlphp security update

March 23, 2018
Cure53 discovered that in SimpleSAMLphp, in rare circumstances an invalid signature on the SAML 2.0 HTTP Redirect binding could be considered valid

Summary

For Debian 7 "Wheezy", these problems have been fixed in version
1.9.2-1+deb7u4.

We recommend that you upgrade your simplesamlphp packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS




Severity
Package : simplesamlphp
Version : 1.9.2-1+deb7u4
CVE ID : CVE-2018-7711

Related News