Bug#949322: python-pysaml2: CVE-2020-5390

2020-02-07 Thread Moritz Mühlenhoff
On Fri, Feb 07, 2020 at 09:59:58AM +0100, Thomas Goirand wrote: > On 1/19/20 9:05 PM, Salvatore Bonaccorso wrote: > > Source: python-pysaml2 > > Version: 4.5.0-5 > > Severity: grave > > Tags: security upstream > > Justification: user security hole > > Control: found -1 4.5.0-4 > > > > Hi, > > >

Bug#949322: python-pysaml2: CVE-2020-5390

2020-02-07 Thread Thomas Goirand
On 1/19/20 9:05 PM, Salvatore Bonaccorso wrote: > Source: python-pysaml2 > Version: 4.5.0-5 > Severity: grave > Tags: security upstream > Justification: user security hole > Control: found -1 4.5.0-4 > > Hi, > > The following vulnerability was published for python-pysaml2. > > CVE-2020-5390[0]:

Bug#949322: python-pysaml2: CVE-2020-5390

2020-01-19 Thread Salvatore Bonaccorso
Source: python-pysaml2 Version: 4.5.0-5 Severity: grave Tags: security upstream Justification: user security hole Control: found -1 4.5.0-4 Hi, The following vulnerability was published for python-pysaml2. CVE-2020-5390[0]: | PySAML2 before 5.0.0 does not check that the signature in a SAML |