-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 23 Mar 2019 13:29:19 +0000 Source: libapache2-mod-auth-mellon Binary: libapache2-mod-auth-mellon Architecture: armhf Version: 0.12.0-2+deb9u1 Distribution: stretch-security Urgency: high Maintainer: armhf / armel Build Daemon (hoiby) Changed-By: Thijs Kinkhorst Description: libapache2-mod-auth-mellon - SAML 2.0 authentication module for Apache Closes: 925197 Changes: libapache2-mod-auth-mellon (0.12.0-2+deb9u1) stretch-security; urgency=high . * Upload to stable-security (closes: #925197) - Auth bypass when used with reverse proxy [CVE-2019-3878] - Open redirect vulnerability in logout [CVE-2019-3877] Checksums-Sha1: 1c1762191d74ce98317b89d48313a054044355c3 164618 libapache2-mod-auth-mellon-dbgsym_0.12.0-2+deb9u1_armhf.deb d8fc571f54283dba76cf4f0e88f0a37d82715850 8675 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_armhf.buildinfo 0a13e3b166a40b8b35b2e56a2333a3b2e51f31ac 56052 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_armhf.deb Checksums-Sha256: 8aebbdb6430342a0581c62a4c1d8c9fe96056765a1d1ff2afed03a77006f0303 164618 libapache2-mod-auth-mellon-dbgsym_0.12.0-2+deb9u1_armhf.deb 9b12b6d81134fddcc440f1543e58151e1d193cd494d01e76f866fce1b1b45360 8675 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_armhf.buildinfo 7c461a78c328e03022738efcbbe4b5209daf890fb655c173f8feb3f957765cf7 56052 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_armhf.deb Files: ee95bb0a92f06f675250bc4b3d377898 164618 debug extra libapache2-mod-auth-mellon-dbgsym_0.12.0-2+deb9u1_armhf.deb c18eaa72fef0418dc0dd4b42a6457e58 8675 web extra libapache2-mod-auth-mellon_0.12.0-2+deb9u1_armhf.buildinfo 0cc3d5ec7cc61c3dfbe0204a22c6a995 56052 web extra libapache2-mod-auth-mellon_0.12.0-2+deb9u1_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEER0G/Nelh/v4vfDD3L3/kibrPJWAFAlyWP7kACgkQL3/kibrP JWDf8BAApeqpqEKSaNrkyaJkwFXyNjlM1okdMwgW5udYxg9lsEUyizsA59slNju5 lxBLcrq2uZyeU6BAJPyKyHK23G6ffJpyBYocSfjr8X5vEPbrXH2pjTRHcMRJ95cf QRuV3dtjY87nKkwSI7e+/855a3v8Av6zK8slyDecoyiZejEfT3sTPTL6vRqEv2ZP E9TzVSzCweIzMXilHlCoissi7R8McInwQTAZ1Y0qEo0MLgBCbb+AgzZSRfY11uFQ YiGVaXxOmG0MpPilGjmy+6Ac6S64xiV/QlpprEynv4NUlIoXpSCowNtNiTfrflCy /7CQZRJRqh2e5e28pyrMiLZhd5Gnd8sxIyH6+tnCiNgdZ/qmc6IGxuM/rZWOLdAR wfMClqTEWvmp3/j9i/Z2iRL4SPvvSW1s54Q/PxoBBcR2GpLza7+XmQMHA16L/Ipw 3Tl4B2OqIeHGpQ1PGJrClQ7BjFVD/10Yiyd/cdpL2UEZ4plmewhSZF7urVk82svf Az8+Wh6yMyomOAdIkSGIHSYnuEn3rASHeW8HLiViAoNwhxoVnWrw8tpsIULrZL8p B/vvl+q4yjzieaz9Mdd04RCXWeCxorCr/1ya7IsV65uUogzwFUIwYLJ/ki+p0QIi ECyxslKj9PLq+fPLlEu/b14Jwv1ktMBUV13YrobA6YkX6MueOLI= =gbOX -----END PGP SIGNATURE-----