USN-3520-1: PySAML2 vulnerability
8 January 2018
PySAML2 could allow authentication without a password.
Releases
Packages
- python-pysaml2 - Pure python implementation of SAML2
Details
It was discovered that PySAML2 incorrectly accepted any password when run
with python optimizations enabled. An attacker could use this issue to
authenticate as any user without a valid password.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 17.10
Ubuntu 17.04
Ubuntu 16.04
In general, a standard system update will make all the necessary changes.