CVE-2017-12872: Debian Linux

Medium severity, CVSS 5.9. EPSS: 1.5% chance of exploitation in the next 30 days.

The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Simplesamlphp Simplesamlphp: up to and including 1.14.11

Published 2017-09-01. Last modified 2026-06-17.