-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 23 Mar 2019 13:29:19 +0000 Source: libapache2-mod-auth-mellon Binary: libapache2-mod-auth-mellon Architecture: mips64el Version: 0.12.0-2+deb9u1 Distribution: stretch-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-aql-02) Changed-By: Thijs Kinkhorst Description: libapache2-mod-auth-mellon - SAML 2.0 authentication module for Apache Closes: 925197 Changes: libapache2-mod-auth-mellon (0.12.0-2+deb9u1) stretch-security; urgency=high . * Upload to stable-security (closes: #925197) - Auth bypass when used with reverse proxy [CVE-2019-3878] - Open redirect vulnerability in logout [CVE-2019-3877] Checksums-Sha1: 0b05988cdeefaaf2df6d5233c6acf6d6b2e2bd44 168096 libapache2-mod-auth-mellon-dbgsym_0.12.0-2+deb9u1_mips64el.deb dbfd51127e3a09a005006c34a13d0b479a62f1ea 8636 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_mips64el.buildinfo a9afc0ebe00aff042bb208cdb5ea07543c86adeb 55442 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_mips64el.deb Checksums-Sha256: fe9e63de5ccfe79bc966c89700ca09e2f1528a3b0e238a0a0cc16ea67f0460a0 168096 libapache2-mod-auth-mellon-dbgsym_0.12.0-2+deb9u1_mips64el.deb f14fb41c162d25326aa1a614da8d591f2ed7c99dd0a378d550bdb938ec859ad5 8636 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_mips64el.buildinfo c382e13837874522506156748a68e6be0a1b56a50fb909ad7ad3655f49a8d6be 55442 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_mips64el.deb Files: da86cc146d057f13c3f637c7ce9e1b49 168096 debug extra libapache2-mod-auth-mellon-dbgsym_0.12.0-2+deb9u1_mips64el.deb b6d909968d2e4b7b9caf55d241d85074 8636 web extra libapache2-mod-auth-mellon_0.12.0-2+deb9u1_mips64el.buildinfo bd278f8ac29add81a8d786efa8d3ba37 55442 web extra libapache2-mod-auth-mellon_0.12.0-2+deb9u1_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvmWu2CcMbNkWs26nnild82864cYFAlyWQNIACgkQnild8286 4cY/iBAAuYI5yUVkZhzFJgKMd1EsBUzaGgM9Nmawu1u2rbtaaU5tNskdOGRVdbHA 6hQ4UBQ5lygCNtBZqNiVzL0tWUctlD8a5GcvgT6IIMUiOBqiuS4PL/+QW+wWpMgt r9ze5WzsyJjVvbfb4yYDC0AH/PGyjY3t3tDHRPpaXu/i0aCek7KSfXKVGOh5qVRm jvB5ZFe3vfyFtEoA8s49/ZUD0gZJzXpykzVJX0BpymcJ5KnVy8zrwr2mk8QfWbaX z2IcSc+TW4BYtIGJlTfQ+cp3xZe1IyqkVeqP3T0IhSeQZc6+/wmGNJblJn7J4mSJ lMh0IltA/OYYDOZvnuEesV8zRvyAKOoFfts8txs6QKARQs8NcIQ7efj6rBdD2oUY wDgRuOtrN+gEQb4MMfJyPXrW2bTu9UAQ3/w8YcramKrVOhmOvwrQ8D6X5aWCo5fz YYx9kvGD7QVztNVwKMfochrkNs7cUbuT0gAFhzUx9oKKJ4xTZgDqF7ih5qkXIqAw StigWCGI+mhVRMsooNuK5Z5B2ztx0Hx7qqxx2bKcQH5E/mhTPNUPouFkXUooJtBX xdj21pWppc+Od1the92bp0JMxKSk4E+YznNiY36YDbUfCEinPt1+B+S+LKqtJITt /xM2mASBOpp5dURiPLRZdhgDcckbhcTfHQlOmiaWjE2zB8StK7g= =KB/U -----END PGP SIGNATURE-----