-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 23 Mar 2019 13:29:19 +0000 Source: libapache2-mod-auth-mellon Binary: libapache2-mod-auth-mellon Architecture: s390x Version: 0.12.0-2+deb9u1 Distribution: stretch-security Urgency: high Maintainer: s390x Build Daemon (zani) Changed-By: Thijs Kinkhorst Description: libapache2-mod-auth-mellon - SAML 2.0 authentication module for Apache Closes: 925197 Changes: libapache2-mod-auth-mellon (0.12.0-2+deb9u1) stretch-security; urgency=high . * Upload to stable-security (closes: #925197) - Auth bypass when used with reverse proxy [CVE-2019-3878] - Open redirect vulnerability in logout [CVE-2019-3877] Checksums-Sha1: 5e1b6f9416f73796ee28f980e7d28cc7da4cc1f6 173790 libapache2-mod-auth-mellon-dbgsym_0.12.0-2+deb9u1_s390x.deb e42e6af773fcd807c183acd6ce8614a57e5c836d 8642 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_s390x.buildinfo 1702dd0327a32cf275b698e5134e5f14a0bc1d21 57470 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_s390x.deb Checksums-Sha256: 433944db96a45da6905db002e2c5d4254a271588d4a093a969c208511c62371a 173790 libapache2-mod-auth-mellon-dbgsym_0.12.0-2+deb9u1_s390x.deb 4b6ecdcbefd94795db6b766b817a869dc7209bed32d941b5765e24752549c39b 8642 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_s390x.buildinfo c538915d60e505686bc131a0abec176a1afa9b1482a6cdd0f1251a0b2e9481c2 57470 libapache2-mod-auth-mellon_0.12.0-2+deb9u1_s390x.deb Files: 86cf1314f92d3a9bc699238fc3629ab0 173790 debug extra libapache2-mod-auth-mellon-dbgsym_0.12.0-2+deb9u1_s390x.deb 5e4164cbd2d45c795372e5c058d3d385 8642 web extra libapache2-mod-auth-mellon_0.12.0-2+deb9u1_s390x.buildinfo fad438d298f587ce7b1789eb723095d2 57470 web extra libapache2-mod-auth-mellon_0.12.0-2+deb9u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEaMR5JIi1/aj4U64lVi3/02CpukIFAlyWPwgACgkQVi3/02Cp ukIi0hAApGsDIrpNUtZnJenpOPJuH9Py51YwrALK6Knr4j1qWn+N6R8GhFyW3cjE ltSD+C3nK1JVQCsZDzcW7dGTlzSNXstEEujJFS01VRj+lmAeVhbfpK4/FtqocVKf H5PsHKgNawvfA068QVH6dHiNhTg2VSIDjHCXP50rgBqhl+24ec3yko7LezIJ8Lxk HfeJM66YaTz41lE+vV5wVe6wfyhR98ckAfUqj3DzbDz4ZrIyLv54uzE57Qq+klU2 fKKlZjET+nIAFRjhUPrktqYB9FlPzbjpMCxB06b24KIv4gMjMN9dlDLGefSMyCvR XGmRu9steR2y8AP8foTl2YCEjsiGG5R0ruTRa1cPzKyKfYl8+XSLZRakMB/uwrIB YDJyCcx29eY+BEse9g610q671eiHzuwO9sPExmBsMgc7v5cel2djxg9jYZQevtPS PM7Io9VD7eZhPRn+SjXgSFdP+4jdKLaPj1fQs7y+76jr1haoWYVUNCajGhgAO6Vn s9bZTrrWopxYGqpLp1/WPPuRh4QvtDtArprhlnDdAF5c5ZlYkplH9EM5EdbMYGf1 un3jAuriOee3srt2aI5t7ujGHS6/m/IRetcHWy8ray89aW17dpPdF4BymuNtLFAn FbuuxmthiwrLkT9XIxQQA65zokkFimYv2T/TAgtydVCdNnW43+4= =UKGM -----END PGP SIGNATURE-----