[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] DSA 4127-1 simplesamlphp

Thijs Kinkhorst thijs at debian.org
Fri Mar 2 06:15:28 UTC 2018


Thijs Kinkhorst pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1c060f9c by Thijs Kinkhorst at 2018-03-02T06:14:45+00:00
DSA 4127-1 simplesamlphp

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -33397,7 +33397,7 @@ CVE-2017-12874 (The InfoCard module 1.0 for SimpleSAMLphp allows attackers to sp
 	NOTE: Patch: https://github.com/simplesamlphp/simplesamlphp-module-infocard/commit/7353762acacd827a61378629f87de991451089da
 CVE-2017-12873 (SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain ...)
 	{DLA-1205-1}
-	- simplesamlphp 1.14.15-1
+	- simplesamlphp 1.14.10-1
 	NOTE: https://simplesamlphp.org/security/201612-04
 	NOTE: Patches: https://github.com/simplesamlphp/simplesamlphp/commit/90dca835158495b173808273e7df127303b8b953aa
 	NOTE: https://github.com/simplesamlphp/simplesamlphp/commit/e2daf4ceb6e580815c3741384b3a09b85a5fc231


=====================================
data/DSA/list
=====================================
--- a/data/DSA/list
+++ b/data/DSA/list
@@ -1,3 +1,7 @@
+[02 Mar 2018] DSA-4127-1 simplesamlphp - security update
+	{CVE-2017-12867 CVE-2017-12869 CVE-2017-12873 CVE-2017-12874 CVE-2017-18121 CVE-2017-18122 CVE-2018-6519 CVE-2018-6521}
+	[jessie] - simplesamlphp 1.13.1-2+deb8u1
+	[stretch] - simplesamlphp 1.14.11-1+deb9u1
 [27 Feb 2018] DSA-4126-1 xmltooling - security update
 	{CVE-2018-0489}
 	[jessie] - xmltooling 1.5.3-2+deb8u3


=====================================
data/dsa-needed.txt
=====================================
--- a/data/dsa-needed.txt
+++ b/data/dsa-needed.txt
@@ -81,8 +81,6 @@ redmine
 --
 ruby2.1/oldstable
 --
-simplesamlphp (thijs)
---
 sqlite3/oldstable
 --
 sssd/stable



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/1c060f9cb2af9056db9903043a3bc9d4467d1a00

---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/1c060f9cb2af9056db9903043a3bc9d4467d1a00
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-commits/attachments/20180302/cf6df42d/attachment.html>


More information about the Secure-testing-commits mailing list