ZeroHour
Ubuntu Security Noticespublished ()ingested

USN-8770-1: SimpleSAMLphp vulnerabilities

AI summary · glm-5.3

Ubuntu patches SimpleSAMLphp signature validation and XXE flaws enabling user impersonation, privilege escalation, and information disclosure.

Ubuntu security notice USN-8770-1 fixes multiple SimpleSAMLphp vulnerabilities. CVE-2019-3465 stems from incorrect cryptographic signature validation in XML messages, allowing an authenticated attacker to impersonate users or gain elevated privileges; it only affected Ubuntu 16.04 LTS and 18.04 LTS. CVE-2024-52596 involves improper handling of external entities when parsing untrusted XML, allowing a remote attacker to obtain sensitive information, and did not affect Ubuntu 24.04 LTS. An additional flaw in signature verification for SAML messages using the HTTP-Redirect binding is also addressed.

  • CVE-2019-3465 allows authenticated attackers to impersonate users or escalate privileges
  • CVE-2024-52596 XXE flaw lets remote attackers obtain sensitive information
  • Older LTS releases most affected; Ubuntu 24.04 LTS unaffected by the XXE issue

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-3465
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML m

Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.

NVD description · AI analysis pending
8.83%
  • xmlseclibs project xmlseclibs
  • xmlseclibs project debian linux
  • xmlseclibs project simplesamlphp
CVE-2024-52596
SimpleSAMLphp xml-common is a common classes for handling XML-structures.

SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 1.19.0.

NVD description · AI analysis pending
8.8<1%
Full article

It was discovered that SimpleSAMLphp incorrectly validated cryptographic signatures in XML messages. An authenticated attacker could possibly use this issue to impersonate users or gain elevated privileges. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-3465) It was discovered that SimpleSAMLphp incorrectly handled external entities when parsing untrusted XML documents. A remote attacker could possibly use this issue to obtain sensitive information. This issue did not affect Ubuntu 24.04 LTS. (CVE-2024-52596) It was discovered that SimpleSAMLphp incorrectly verified signatures in SAML messages using the HTTP-Redirect binding. A remote attacker could possibly use…

This source does not provide full text. Read it at ubuntu.com.