Candidate: CVE-2011-4625 PublicDate: 2019-11-06 15:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4625 Description: simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_simplesamlphp: vendor: http://lists.debian.org/debian-security-announce/2011/msg00206.html upstream_simplesamlphp: released (1.8.2-1) hardy_simplesamlphp: DNE lucid_simplesamlphp: DNE maverick_simplesamlphp: ignored (reached end-of-life) natty_simplesamlphp: ignored (reached end-of-life) oneiric_simplesamlphp: ignored (reached end-of-life) precise_simplesamlphp: released (1.8.2-1) quantal_simplesamlphp: released (1.8.2-1) raring_simplesamlphp: released (1.8.2-1) devel_simplesamlphp: released (1.8.2-1)