CVE-2017-12872: Infoleak
Multiple timing side-channel issues
Other sources
The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAMLSession class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12872?
CVE-2017-12872 has a medium severity rating due to the potential for remote attackers to exploit timing side-channel issues.
How do I fix CVE-2017-12872?
To fix CVE-2017-12872, upgrade SimpleSAMLphp to version 1.15.0-rc1 or later.
What software is affected by CVE-2017-12872?
CVE-2017-12872 affects SimpleSAMLphp versions 1.14.11 and earlier, including any versions from 1.12.0 to 1.14.12.
Can CVE-2017-12872 lead to unauthorized access?
Yes, CVE-2017-12872 may allow attackers to perform timing attacks that could lead to unauthorized access to sensitive information.
Is CVE-2017-12872 limited only to SimpleSAMLphp?
While CVE-2017-12872 primarily affects SimpleSAMLphp, it highlights broader issues related to timing attacks that can impact other applications if they use similar comparison techniques.