The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://simplesamlphp.org/security/201703-01 | patch vendor advisory |
https://lists.debian.org/debian-lts-announce/2017/12/msg00007.html | third party advisory mailing list |
https://lists.debian.org/debian-lts-announce/2018/06/msg00017.html | third party advisory mailing list |