CVE-2016-9955: Debian Linux

Medium severity, CVSS 6.3. EPSS: 1.2% chance of exploitation in the next 30 days.

The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.

Affected products

  • Debian Debian Linux: version 7.0 only
  • Simplesamlphp Simplesamlphp: before 1.14.11 (fixed in 1.14.11)

Published 2017-02-17. Last modified 2026-06-17.