simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.
The product does not handle or incorrectly handles an exceptional condition.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2011-4625 | third party advisory |
https://www.mageni.net/1.3.6.1.4.1.25623.1.0.70545 | third party advisory |