Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-1983-1 simplesamlphp security update
Debian DSA Debian DSA DSA-4560-1 simplesamlphp security update
EUVD EUVD EUVD-2019-0760 Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.
Github GHSA Github GHSA GHSA-pqm6-cgwr-x6pf Signature validation bypass in XmlSecLibs
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
https://github.com/robrichards/xmlseclibs/commit/0a53d3c3aa87564910cae4ed01416441d3ae0db5 cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2019/11/msg00003.html cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7KID7C4AZPYYIZQIPSLANP4R2RQR6YK3/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AB34ILMJ67CUROBOR6YPKB46VHXLOAJ4/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BBKVDUZ7G5ZOUO4BFJWLNJ6VOKBQJX5U/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BNFMY5RRLU63P25HEBVDO5KAVI7TX7JV/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ESKJTWLE7QZBQ3EKMYXKMBQG3JDEJWM6/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HBE2SJSXG7J4XYLJ2H6HC2VPPOG2OMUN/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MAWOVYLZKYDCQBLQEJCFAAD3KQTBPHXE/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OCSR3V6LNWJAD37VQB6M2K7P4RQSCVFG/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XBSSRV5Q7JFCYO46A3EN624UZ4KXFQ2M/ cve-icon cve-icon
https://seclists.org/bugtraq/2019/Nov/8 cve-icon cve-icon
https://simplesamlphp.org/security/201911-01 cve-icon cve-icon
https://www.debian.org/security/2019/dsa-4560 cve-icon cve-icon
https://www.tenable.com/security/tns-2019-09 cve-icon cve-icon
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.03746}

epss

{'score': 0.03054}


cve-icon MITRE

Status: PUBLISHED

Assigner: debian

Published:

Updated: 2024-08-04T19:12:09.411Z

Reserved: 2018-12-31T00:00:00

Link: CVE-2019-3465

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-07T20:15:11.090

Modified: 2024-11-21T04:42:06.050

Link: CVE-2019-3465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.