Your message dated Sun, 30 Aug 2026 15:06:07 +0200
with message-id <[email protected]>
and subject line Re: Accepted libcatalyst-plugin-authentication-perl 0.10028-1
(source) into unstable
has caused the Debian Bug report #1139461,
regarding libcatalyst-plugin-authentication-perl: CVE-2009-10007
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1139461: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139461
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libcatalyst-plugin-authentication-perl
Version: 0.10026-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for
libcatalyst-plugin-authentication-perl.
CVE-2009-10007[0]:
| Catalyst::Plugin::Authentication versions before 0.10_027 for Perl
| is susceptible to session fixation attacks.
| Catalyst::Plugin::Authentication does not automatically change the
| session id after authentication. An attacker that obtains a session
| id cookie can use this to impersonate the victim.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2009-10007
https://www.cve.org/CVERecord?id=CVE-2009-10007
[1] https://lists.security.metacpan.org/cve-announce/msg/40832427/
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: libcatalyst-plugin-authentication-perl
Source-Version: 0.10028-1
On Sun, Aug 30, 2026 at 12:34:12PM +0000, Debian FTP Masters wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA512
>
> Format: 1.8
> Date: Sun, 30 Aug 2026 14:20:44 +0200
> Source: libcatalyst-plugin-authentication-perl
> Architecture: source
> Version: 0.10028-1
> Distribution: unstable
> Urgency: medium
> Maintainer: Debian Perl Group <[email protected]>
> Changed-By: gregor herrmann <[email protected]>
> Changes:
> libcatalyst-plugin-authentication-perl (0.10028-1) unstable; urgency=medium
> .
> * Team upload.
> * Import upstream version 0.10028.
> Includes changes in 0.10_027:
> - When used with Catalyst::Plugin::Session, rotate the session id after a
> successful login to avoid session fixation attacks (CVE-2009-10007).
> * Drop pod-spelling.patch, fixed upstream.
> Checksums-Sha1:
> b24e41732d3371dd274867495de5e60d93dd6df8 2985
> libcatalyst-plugin-authentication-perl_0.10028-1.dsc
> 7011df8b515099b35dc93e59f866c8410987840e 63552
> libcatalyst-plugin-authentication-perl_0.10028.orig.tar.gz
> 4131ac296738f9fda3024f305a9f68ff6a53c6b3 3052
> libcatalyst-plugin-authentication-perl_0.10028-1.debian.tar.xz
> 2d499c4c2226bb8e6487387e89e7245d2c3b80db 167036
> libcatalyst-plugin-authentication-perl_0.10028-1.git.tar.xz
> 7c1570bd6278ca025b61dfc99d3f81291f35a5c2 17800
> libcatalyst-plugin-authentication-perl_0.10028-1_source.buildinfo
> Checksums-Sha256:
> b205016947d938063361cd34d4c248bdcbc87f5933aa00b9a54366612cb33a8f 2985
> libcatalyst-plugin-authentication-perl_0.10028-1.dsc
> c219c6422d8e4ca554535838625b4bd313eeca5151f54ab942af8aa7be360c0d 63552
> libcatalyst-plugin-authentication-perl_0.10028.orig.tar.gz
> 3f18042cfecaac3033c2d964eb7fc4445d6dac289479828c6652a014778c53db 3052
> libcatalyst-plugin-authentication-perl_0.10028-1.debian.tar.xz
> 748ad7881d8961cf8c8cd5a80c18e0f118d3b2a59446a02a00d441ad1c6f8e56 167036
> libcatalyst-plugin-authentication-perl_0.10028-1.git.tar.xz
> b558253ed2096ba3d3c41f8c838c21dc3d998533230a424ac976da1d704275bc 17800
> libcatalyst-plugin-authentication-perl_0.10028-1_source.buildinfo
> Files:
> d67c5b86de93e0de271f0f80d063cad0 2985 perl optional
> libcatalyst-plugin-authentication-perl_0.10028-1.dsc
> 8452178a6af6c3e2fef51c8b0f0a8037 63552 perl optional
> libcatalyst-plugin-authentication-perl_0.10028.orig.tar.gz
> 85dae1d0b785707b5c39968efdfc4bd2 3052 perl optional
> libcatalyst-plugin-authentication-perl_0.10028-1.debian.tar.xz
> 504f0ef31ad8583cf05474b2da573263 167036 perl None
> libcatalyst-plugin-authentication-perl_0.10028-1.git.tar.xz
> 028615e25c096d66038f28d1a4f798bd 17800 perl optional
> libcatalyst-plugin-authentication-perl_0.10028-1_source.buildinfo
> Git-Tag-Info: tag=c24028bbabb5c179c79666953886af331b65a0ed
> fp=d1e1316e93a760a8104d85fabb3a68018649aa06
> Git-Tag-Tagger: gregor herrmann <[email protected]>
>
> -----BEGIN PGP SIGNATURE-----
>
> iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqUIQ0ACgkQYG0ITkaD
> wHkLTRAAg/IEWeDqeshB1eGf3qP0ixytgxSUfccme5HPQLHcahmwI3X7WKn0sGX9
> f416euuNrL0+VZosXvIZHq3HhZwXjhePxGdn+B/kgPb4Anpg5n8VDSOvRKaNzI5L
> lPEyNkJv+asVOA9ncGueY4pJ796SvyWF5ad4FHPuzfwBI/L6WI7Zbs19CH1spp5+
> GoID9StTVoj9amWKidpbwClVl2I2FuAqNcbJoE4xLyDdxV/BXhGPdfCKiO/PGPz8
> NuGrwM4IDMJDCw+qh3tdnkeiRzZ8ygeXXQl3887obpI7+jP4scBTC4DdnM4yhLew
> oUFK/Zq0XTDchon7DTGQqoCPuC//P3K/psXQfx4jS/wy46YYceMQ6W2NtRdpFJkR
> IImVRSfy1D8FWOC3w8+/+uZtGUAvJ/JDSQfvWQYEY60RPo59a6+wFdg8HxhVY8Na
> PJzyUKLtjy0cXqFxJtWFua2l2rwBMWfqm4WbwfKFMqbaJPs6mr/daw2llxzVxWz6
> yDG2r5hy5xAh6aUlLjxMWOyrsXrWJI0XlIUhRMaJ+SbB+7XH5VKhtZrtU2tfkKsh
> TgVT0ohdn28cvXpp2W1s4c5Q4UvLr6VMVW1X9DwBojHi0Qc+0Vo2MxxnREESVIrO
> L/Qn51cDdYQoj5ObQZo/wg0eFCEVeWZ8b4bEKnOdGmOlmZrhC+o=
> =RqDJ
> -----END PGP SIGNATURE-----
--- End Message ---