This bug was fixed in the package opensaml - 3.2.1-4.1ubuntu0.24.04.1
---------------
opensaml (3.2.1-4.1ubuntu0.24.04.1) noble-security; urgency=medium
* SECURITY UPDATE: CPPOST-126 - Simple signature verification fails to
detect parameter smuggling (LP: #2103420)
- debian/patches/lp2103420-forging.patch: address parameter smuggling.
Patch from upstream commit 22a610b322e2178abd03e97cdbc8fb50b45efaee,
thanks to Scott Cantor
- No CVE number
-- Tom Andrew <[email protected]> Tue, 18 Mar 2025 16:24:50 +0000
** Changed in: opensaml (Ubuntu Noble)
Status: Fix Committed => Fix Released
** Changed in: opensaml (Ubuntu Focal)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to the bug report.
https://bugs.launchpad.net/bugs/2103420
Title:
Security issue with libsaml12
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/opensaml/+bug/2103420/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs