-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 23 Mar 2019 13:29:19 +0000 Source: libapache2-mod-auth-mellon Binary: libapache2-mod-auth-mellon Architecture: arm64 Version: 0.12.0-2+deb9u1 Distribution: stretch-security Urgency: high Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Thijs Kinkhorst Description: libapache2-mod-auth-mellon - SAML 2.0 authentication module for Apache Closes: 925197 Changes: libapache2-mod-auth-mellon (0.12.0-2+deb9u1) stretch-security; urgency=high . * Upload to stable-security (closes: #925197) - Auth bypass when used with reverse proxy [CVE-2019-3878] - Open redirect vulnerability in logout [CVE-2019-3877] Checksums-Sha1: e6ef83c9dad601a71172e555644530bd37ed35f0 167962 libapache2-mod-auth-mellon-dbgsym_0.12.0-2+deb9u1_arm64.deb 5a978e72bf5c3adf0e7dd5107d3b1108230d9c84 8705 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_arm64.buildinfo 0995d6fc47ec61d7071f510c545aa0bb75704f27 54362 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_arm64.deb Checksums-Sha256: 3be76adcfbfcd47166da6d494ee5adff8f2aeae3666b226be748704d299b18e9 167962 libapache2-mod-auth-mellon-dbgsym_0.12.0-2+deb9u1_arm64.deb 35810a92da2f8ab5eb39ccd949cb3a1179616b7f788c6860bbfb71385ea7d9af 8705 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_arm64.buildinfo 84deeb3794a48be16a6c68a4e1aad385640738dba4fb55556ed3784eb2512230 54362 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_arm64.deb Files: cefc9102591a5afa3144aedda54585c1 167962 debug extra libapache2-mod-auth-mellon-dbgsym_0.12.0-2+deb9u1_arm64.deb 3158f2bcb5956b5860327a436ac6f725 8705 web extra libapache2-mod-auth-mellon_0.12.0-2+deb9u1_arm64.buildinfo be7cd2f7c2682943fe410cee4f24cc42 54362 web extra libapache2-mod-auth-mellon_0.12.0-2+deb9u1_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE6I7LAZ94rdGzoRFJgTjochSsEVUFAlyWP4oACgkQgTjochSs EVUFfA/9EUDlx+/z2CI5zuqhDrN4umKtyJ47orTvPe27H6dE5WuyaRKUUQKik9y/ mFWdPhrgiI3j4lk7eBBH1UoFdA9ZsVxlYV0E+mT8xtCGc9qPc/rjAd/3eGaR9IdK Ai2T4+aI3h2oYnEadf80wvU46JmUo9x2v9Mn7AkYB2hD78P0Tj/zj7T6vf7QD0Z+ /Q9VHBWH1NE1vjCCDJWc9X1wRmXlBWRyvhLA0RzW2tADc00xndjpucSeDcnx2ZQf Qm8vu9FeAWNZEN2qJu8p69/qJaDHWG73KJGuOz0B88Fz7As/iDFjLRj/EYlEyBmv dhMToIIzpI/vZeihEKuVpS2w9t6XvJvCdgln7YcUv2TAw+XxeOXPo/FtYTat46KS 6QveJmMioM0EZocD3V5iVfZaZ7Y8+UzNyOD9/4Po9t7mY3lbQmr90x0CsUi/D3fI 4oDGXdrRrOZVeei/3pIC6vLAf1oudK2+3PxbLHzvCse7UJ4lcncZlp5Y/NyMGELr 8ttDu2GTbmwNRSe/6nIVCyLccnSKveKdxG4d2yvtpO0bSyOHm1slEK0pNEt4XNjD oLKiaVboX2BLhIGYnch/VGSy23XkxQYvKDX4j7JG776D+0YzFzhXrhjTjFk9xpEg 5C1Am+nQuZGRMMmMwWagrYBI/Ekt6pLwC+itEWXhXf0w12cIZJ0= =XRQf -----END PGP SIGNATURE-----