CVE-2017-1000246
17.11.2017, 04:29
Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.Enginsight
Vendor | Product | Version |
---|---|---|
pysaml2_project | pysaml2 | 𝑥 < 4.6.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python-pysaml2 |
|
Common Weakness Enumeration