MEDIUM5.9
GHSA-v882-949x-6v28
SimpleSAMLphp allows timing side-channel attacks
Quick fix
GHSA-v882-949x-6v28 — simplesamlphp/simplesamlphp: upgrade to the fixed version with the command below.
composer require simplesamlphp/simplesamlphp:^1.15.0-rc1Details
The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/simplesamlphp/simplesamlphp
Introduced in:
0Fixed in: 1.15.0-rc1Fix
composer require simplesamlphp/simplesamlphp:^1.15.0-rc1References
- https://nvd.nist.gov/vuln/detail/CVE-2017-12872[ADVISORY]
- https://github.com/simplesamlphp/simplesamlphp/commit/b72c79e3070f930d758f5c269333d63ed7509e2e[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/simplesamlphp/simplesamlphp/CVE-2017-12872.yaml[WEB]
- https://lists.debian.org/debian-lts-announce/2017/12/msg00007.html[WEB]
- https://lists.debian.org/debian-lts-announce/2018/06/msg00017.html[WEB]
- https://simplesamlphp.org/security/201703-01[WEB]