CVE for upcoming ODBC issue in Shibboleth SP

Cantor, Scott cantor.2 at osu.edu
Wed Sep 3 16:49:01 BST 2025


> I asked the Debian Security Team to allocate a CVE ID for
> the upcoming issue. They only do that for yet
>-undisclosed issues, so the timing isca
> bit tight, though; we'll see. 

If you think tomorrow is likely, I can hold the release. I'm building the packages now but I can re-hide the directory once that's done this afternoon and just wait on the CVE.

-- Scott




More information about the Pkg-shibboleth-devel mailing list