simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.
| Software | From | Fixed in |
|---|---|---|
simplesamlphp / simplesamlphp
|
1.8.0 | 1.8.2 |
simplesamlphp / simplesamlphp
|
1.6.0 | 1.6.3 |
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10.0 | 10.0.x |