------------------------------------------------------------------------- Debian LTS Advisory DLA-4161-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Tobias Frost May 09, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : simplesamlphp Version : 1.19.0-1+deb11u2 CVE ID : CVE-2025-27773 Debian Bug : 1100595 A vulnerability has been discovered in SimpleSAMLphp, a framework for authentication, primarily via the SAML protocol. CVE-2025-27773 The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.17.0 and 5.0.0-alpha.20, there is a signature confusion attack in the HTTPRedirect binding. An attacker with any signed SAMLResponse via the HTTP-Redirect binding can cause the application to accept an unsigned message. Versions 4.17.0 and 5.0.0-alpha.20 contain a fix for the issue. For Debian 11 bullseye, this problem has been fixed in version 1.19.0-1+deb11u2. We recommend that you upgrade your simplesamlphp packages. For the detailed security status of simplesamlphp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/simplesamlphp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment:
signature.asc
Description: PGP signature