SimpleSAMLphp 1.15.4

103 views
Skip to first unread message

Jaime Perez Crespo

unread,
Mar 5, 2018, 10:22:21 AM3/5/18
to simplesamlp...@googlegroups.com, SimpleSAMLphp
Hi,

SimpleSAMLphp 1.15.4 has been released. This is a security release related to the following issue:

https://simplesamlphp.org/security/201803-01

This issue as been rated with medium risk, affecting mostly SimpleSAMLphp service providers. Although the consequences of the issue are serious, we consider it to be difficult to exploit, involving in most case human intervention by the SP operators. In any case, and as usual, we recommend upgrading as soon as possible.

Please refer to the changelog for more information. The changelog and upgrade notes are available here, respectively:

https://simplesamlphp.org/docs/stable/simplesamlphp-changelog
https://simplesamlphp.org/docs/stable/simplesamlphp-upgrade-notes-1.15

The new release is available for download here:

https://github.com/simplesamlphp/simplesamlphp/releases/download/v1.15.4/simplesamlphp-1.15.4.tar.gz

You can verify the integrity of this file by comparing the SHA256 digest: 349cf5d9f9ecbbced0e6f6794d26d5242fc9dafbd34268aeeb200182c24f88a5

Regards,


Jaime Pérez
UNINETT / Feide

jaime...@uninett.no
jaime...@protonmail.com
9A08 EA20 E062 70B4 616B 43E3 562A FE3A 6293 62C2

"Two roads diverged in a wood, and I, I took the one less traveled by, and that has made all the difference."
- Robert Frost

Jaime Perez Crespo

unread,
Mar 7, 2018, 3:12:16 AM3/7/18
to simplesamlp...@googlegroups.com, SimpleSAMLphp
Hi,

CVE ID 2018-7711 has been assigned to SSPSA 201803-01:

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7711
Reply all
Reply to author
Forward
0 new messages