Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a1f21165 by Salvatore Bonaccorso at 2025-05-12T06:46:55+02:00
Mark simplesamlphp as no-dsa and remove from dsa-needed list
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -20159,6 +20159,7 @@ CVE-2025-27789 (Babel is a compiler for writing next
generation JavaScript. When
CVE-2025-27773 (The SimpleSAMLphp SAML2 library is a PHP library for SAML2
related fun ...)
{DLA-4161-1}
- simplesamlphp 1.19.7-2 (bug #1100595)
+ [bookworm] - simplesamlphp <no-dsa> (Will be fixed via point release)
NOTE:
https://github.com/simplesamlphp/saml2/security/advisories/GHSA-46r4-f8gj-xg56
NOTE:
https://github.com/simplesamlphp/saml2/commit/7867d6099dc7f31bed1ea10e5bea159c5623d2a0
NOTE: SimpleSAMLphp SAML2 library embedded in simplesamlphp
=====================================
data/dsa-needed.txt
=====================================
@@ -53,8 +53,6 @@ ring
ruby-saml
Utkarsh Gupta might work on an update
--
-simplesamlphp
---
sogo
--
sympa
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a1f21165664ebbd5f28fadf16c5424cf663a5ce1
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a1f21165664ebbd5f28fadf16c5424cf663a5ce1
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits