Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
A vulnerability has been discovered in SimpleSAMLphp, a framework for authentication, primarily via the SAML protocol. CVE-2025-27773 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4161-1
It was discovered that in SimpleSAMLphp, an implementation of the SAML 2.0 protocol, is prone to an XXE vulnerability when loading an (untrusted) XML document. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3981-1
It was discovered that in SimpleSAMLphp, an implementation of the SAML 2.0 protocol, is prone to a XXE vulnerability when loading an (untrusted) XML document. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5822-1
It was discovered that in SimpleSAMLphp, an implementation of the SAML 2.0 protocol, it was possible to circumvent XML signature verification on SAML messages. . Package : simplesamlphp Version : 1.13.1-2+deb8u3 CVE ID : CVE-2019-3465 Debian Bug : 944107 It was discovered that in SimpleSAMLphp, an implementation of the SAML 2.0 protocol, it was possible to circumvent XML signature verification on SAML messages. For Debian 8 "Jessie", this problem has been fixed in version 1.13.1-2+deb8u3. We recommend that you upgrade your simplesamlphp packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade SimpleSAMLphp on Debian 8 to enhance security and mitigate XML signature verification bypass vulnerabilities by following these essential steps. simplesamlphp, XML signature, Debian security, protocol update, security fix. . Severity: Critical. LinuxSecurity.com Team
It was discovered that in SimpleSAMLphp, an implementation of the SAML 2.0 protocol, it was possible to circumvent XML signature verification on SAML messages. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4560-1
CVE-2017-12872 / CVE-2017-12868 The (1) Htpasswd authentication source in the authcrypt module and (2) . Package : simplesamlphp Version : 1.13.1-2+deb8u2 CVE ID : CVE-2017-12868 CVE-2017-12872 CVE-2017-12872 / CVE-2017-12868 The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input. CVE-2017-12868 was a about an improper fix of CVE-2017-12872 in the initial patch released by upstream. We have used the correct patch. For Debian 8 "Jessie", these problems have been fixed in version 1.13.1-2+deb8u2. We recommend that you upgrade your simplesamlphp packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade the authcrypt module in simplesamlphp on Debian 8 to resolve timing attack vulnerabilities. Follow the detailed guide for a successful update. Debian LTS, Simplesamlphp Security Update, Authcrypt Module, Timing Attack, Security Patching. . Severity: Critical. LinuxSecurity.com Team
Cure53 discovered that in SimpleSAMLphp, in rare circumstances an invalid signature on the SAML 2.0 HTTP Redirect binding could be considered valid. . Package : simplesamlphp Version : 1.9.2-1+deb7u4 CVE ID : CVE-2018-7711 Cure53 discovered that in SimpleSAMLphp, in rare circumstances an invalid signature on the SAML 2.0 HTTP Redirect binding could be considered valid. Additionally this update fixes a regression introduced in DLA-1298 by the backported patch for SSA-201802-01/CVE-2018-7644. For Debian 7 "Wheezy", these problems have been fixed in version 1.9.2-1+deb7u4. We recommend that you upgrade your simplesamlphp packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A recent patch for SimpleSAMLphp rectifies an issue with signatures that may mistakenly appear valid under certain circumstances.. Debian Security, SimpleSAMLphp Update, Signature Validation, Critical Fix. . Severity: Critical. LinuxSecurity.com Team
Several vulnerabilities have been discovered in SimpleSAMLphp, a framework for authentication, primarily via the SAML protocol. CVE-2016-9814 & CVE-2016-9955 . Package : simplesamlphp Version : 1.9.2-1+deb7u3 CVE ID : CVE-2016-9814 CVE-2016-9955 Several vulnerabilities have been discovered in SimpleSAMLphp, a framework for authentication, primarily via the SAML protocol. CVE-2016-9814 & CVE-2016-9955 An incorrect check of return values in the signature validation utilities allowed an attacker to get invalid signatures accepted as valid in the rare case of an error occurring during validation. SSPSA-201802-01 (no CVE yet) Critical signature validation vulnerability. In addition this update adds a patch to solve excessive resource consumption in case of SimpleSAMLphp processing a large metadata file. For Debian 7 "Wheezy", these problems have been fixed in version 1.9.2-1+deb7u3. We recommend that you upgrade your simplesamlphp packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Important security patch for SimpleSAMLphp addresses login failures and excessive resource usage on Debian 7 systems.. Debian LTS, Simplesamlphp, Authentication Issues. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.