First published: Thu Jan 25 2018(Updated: )
Denial of Service in timestamp validation function
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/simplesamlphp/saml2 | <1.10.4>=2.0<2.3.5>=3.0<3.1.1 | |
debian/simplesamlphp | 1.16.3-1+deb10u2 1.16.3-1+deb10u1 1.19.0-1 1.19.7-1 | |
composer/simplesamlphp/saml2 | >=3.0<3.1.1 | 3.1.1 |
composer/simplesamlphp/saml2 | >=2.0<2.3.5 | 2.3.5 |
composer/simplesamlphp/saml2 | <1.10.4 | 1.10.4 |
SimpleSAMLphp | >=1.0.0<1.10.4 | |
SimpleSAMLphp | >=2.0.0<2.3.5 | |
SimpleSAMLphp | >=3.0.0<3.1.1 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6519 is a vulnerability in the timestamp validation function of the SAML2 library in SimpleSAMLphp.
The severity of CVE-2018-6519 is high with a CVSS score of 7.5.
CVE-2018-6519 affects SimpleSAMLphp versions before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1.
To fix CVE-2018-6519, upgrade SimpleSAMLphp to version 1.10.4 or higher for versions 1.x, version 2.3.5 or higher for versions 2.x, and version 3.1.1 or higher for versions 3.x.
You can find more information about CVE-2018-6519 at the following references: [link1], [link2], [link3].