Re: libapache2-mod-auth-openidc in Bullseye

2021-08-01 Thread Salvatore Bonaccorso
Hi Christoph, On Fri, Jul 30, 2021 at 12:25:11PM +0200, Christoph Martin wrote: > Dear Release Team, > > currently the version 2.4.4.1-2 of libapache2-mod-auth-openidc is in > testing/bullseye . Some days ago four CVE security bugs were published > which are fixed in version 2.4.9 . > > The fix

libapache2-mod-auth-openidc in Bullseye

2021-07-30 Thread Christoph Martin
Dear Release Team, currently the version 2.4.4.1-2 of libapache2-mod-auth-openidc is in testing/bullseye . Some days ago four CVE security bugs were published which are fixed in version 2.4.9 . The fix to CVE-2021-32791 looks quite big, so that I think it is not safe to backport it to 2.4.4.1 lik