CVE-2017-1000246
17.11.2017, 04:29
Python package pysaml2 version 4.4.0 and earlier reuses the initialization vector across encryptions in the IDP server, resulting in weak encryption of data.Enginsight
| Vendor | Product | Version |
|---|---|---|
| pysaml2_project | pysaml2 | 𝑥 < 4.6.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python-pysaml2 |
|
Common Weakness Enumeration