The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
https://www.debian.org/security/2018/dsa-4127
https://simplesamlphp.org/security/201612-03
https://lists.debian.org/debian-lts-announce/2017/12/msg00007.html