Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Chris Czub

Researcher fromDuo Security
#17677of 53,635
15.2Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2017-12741
5.9
2017-09-01
Simplesamlphp · Simplesamlphp · CVE-2017-12871
**Name of the Vulnerable Software and Affected Versions** SimpleSAMLphp versions 1.14.x through 1.14.11 **Description** The issue makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging the use of the first 16 bytes of the `secret key` as the initialization vector (IV) in the `aesEncrypt` method. **Recommendations** For SimpleSAMLphp versions 1.14.x through 1.14.11, consider modifying the `aesEncrypt` method in `lib/SimpleSAML/Utils/Crypto.php` to use a secure initialization vector (IV) instead of the first 16 bytes of the `secret key`. As a temporary workaround, restrict access to the `aesEncrypt` method until a patch is available.
PT-2016-5769
9.3
2016-06-03
Lenovo · Lenovo Accelerator Application · CVE-2016-3944
**Name of the Vulnerable Software and Affected Versions** Lenovo Accelerator Application (affected versions not specified) **Description** The issue allows man-in-the-middle attackers to execute arbitrary code by spoofing an update response from the `susapi.lenovomm.com` API endpoint. This is due to a flaw in the UpdateAgent component. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.