Thijs Kinkhorst pushed to branch master at Debian Security Tracker / security-tracker
Commits: 1c060f9c by Thijs Kinkhorst at 2018-03-02T06:14:45+00:00 DSA 4127-1 simplesamlphp - - - - - 3 changed files: - data/CVE/list - data/DSA/list - data/dsa-needed.txt Changes: ===================================== data/CVE/list ===================================== --- a/data/CVE/list +++ b/data/CVE/list @@ -33397,7 +33397,7 @@ CVE-2017-12874 (The InfoCard module 1.0 for SimpleSAMLphp allows attackers to sp NOTE: Patch: https://github.com/simplesamlphp/simplesamlphp-module-infocard/commit/7353762acacd827a61378629f87de991451089da CVE-2017-12873 (SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain ...) {DLA-1205-1} - - simplesamlphp 1.14.15-1 + - simplesamlphp 1.14.10-1 NOTE: https://simplesamlphp.org/security/201612-04 NOTE: Patches: https://github.com/simplesamlphp/simplesamlphp/commit/90dca835158495b173808273e7df127303b8b953aa NOTE: https://github.com/simplesamlphp/simplesamlphp/commit/e2daf4ceb6e580815c3741384b3a09b85a5fc231 ===================================== data/DSA/list ===================================== --- a/data/DSA/list +++ b/data/DSA/list @@ -1,3 +1,7 @@ +[02 Mar 2018] DSA-4127-1 simplesamlphp - security update + {CVE-2017-12867 CVE-2017-12869 CVE-2017-12873 CVE-2017-12874 CVE-2017-18121 CVE-2017-18122 CVE-2018-6519 CVE-2018-6521} + [jessie] - simplesamlphp 1.13.1-2+deb8u1 + [stretch] - simplesamlphp 1.14.11-1+deb9u1 [27 Feb 2018] DSA-4126-1 xmltooling - security update {CVE-2018-0489} [jessie] - xmltooling 1.5.3-2+deb8u3 ===================================== data/dsa-needed.txt ===================================== --- a/data/dsa-needed.txt +++ b/data/dsa-needed.txt @@ -81,8 +81,6 @@ redmine -- ruby2.1/oldstable -- -simplesamlphp (thijs) --- sqlite3/oldstable -- sssd/stable View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/1c060f9cb2af9056db9903043a3bc9d4467d1a00 --- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/1c060f9cb2af9056db9903043a3bc9d4467d1a00 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ Secure-testing-commits mailing list Secure-testing-commits@lists.alioth.debian.org http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-commits