Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA 1895-2] New opensaml2 and shibboleth-sp2 packages fix r

    From Florian Weimer@1:229/2 to All on Fri Oct 9 21:10:06 2009
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1895-2 [email protected] http://www.debian.org/security/ Florian Weimer October 09, 2009 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : opensaml2, shibboleth-sp2
    Vulnerability : interpretation conflict
    Problem type : remote
    Debian-specific: no
    Debian Bugs : 549936

    In DSA-1895-1, the xmltooling package was updated to address several
    security issues. It turns out that the change related to SAML
    metadata processing for key constraints caused problems when applied
    without the matching changes in the opensaml2 and shibboleth-sp2
    packages.

    For the stable distribution (lenny), this problem has been fixed in
    version 2.0-2+lenny1 of the opensaml2 packages, and version
    2.0.dfsg1-4+lenny1 of the shibboleth-sp2 packages.

    We recommend that you upgrade your opensaml2 and shibboleth-sp2
    packages.

    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 5.0 alias lenny
    - --------------------------------

    Source archives:

    http://security.debian.org/pool/updates/main/s/shibboleth-sp2/shibboleth-sp2_2.0.dfsg1-4+lenny1.dsc
    Size/MD5 checksum: 1671 6aa8c0c382f42d56da0d02a8dac190f1
    http://security.debian.org/pool/updates/main/o/opensaml2/opensaml2_2.0.orig.tar.gz
    Size/MD5 checksum: 705058 85968f3c72cb789b11c9d01209e4d46b
    http://security.debian.org/pool/updates/main/o/opensaml2/opensaml2_2.0-2+lenny1.dsc
    Size/MD5 checksum: 1449 5c628a5dd4614555953e410a78009298
    http://security.debian.org/pool/updates/main/s/shibboleth-sp2/shibboleth-sp2_2.0.dfsg1-4+lenny1.diff.gz
    Size/MD5 checksum: 14500 df59094fab5f3714e6ce67b298d9fbf3
    http://security.debian.org/pool/updates/main/s/shibboleth-sp2/shibboleth-sp2_2.0.dfsg1.orig.tar.gz
    Size/MD5 checksum: 726871 836fccbf614fc8edfc1fdbefcf0ba489
    http://security.debian.org/pool/updates/main/o/opensaml2/opensaml2_2.0-2+lenny1.diff.gz
    Size/MD5 checksum: 6582 2c4fe0169aa897da269107fe43727965

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/o/opensaml2/opensaml2-schemas_2.0-2+lenny1_all.deb
    Size/MD5 checksum: 22936 3524f5c9de24e6dd6ce655099534a5ec
    http://security.debian.org/pool/updates/main/s/shibboleth-sp2/libshibsp-doc_2.0.dfsg1-4+lenny1_all.deb
    Size/MD5 checksum: 216996 38cac8e6036637aa770ba325ae3ea83b
    http://security.debian.org/pool/updates/main/s/shibboleth-sp2/shibboleth-sp2-schemas_2.0.dfsg1-4+lenny1_all.deb
    Size/MD5 checksum: 15144 eb73f6bbbdcc8152f7f29b78a7855282
    http://security.debian.org/pool/updates/main/o/opensaml2/libsaml2-doc_2.0-2+lenny1_all.deb
    Size/MD5 checksum: 320978 8f55a5e0788336b563241aa9787e4f19

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/o/opensaml2/opensaml2-tools_2.0-2+lenny1_alpha.deb
    Size/MD5 checksum: 30830 56a3df9d8f29260549dc1b0ad30c6c73
    http://security.debian.org/pool/updates/main/s/shibboleth-sp2/libshibsp1_2.0.dfsg1-4+lenny1_alpha.deb
    Size/MD5 checksum: 935782 bc072664522bf99d89c9e59b7ee5795a
    http://security.debian.org/pool/updates/main/o/opensaml2/libsaml2-dev_2.0-2+lenny1_alpha.deb
    Size/MD5 checksum: 44900 d077afefbc80465fda7d6e667edaafe0
    http://security.debian.org/pool/updates/main/s/shibboleth-sp2/libapache2-mod-shib2_2.0.dfsg1-4+lenny1_alpha.deb
    Size/MD5 checksum: 240726 71c5d7f685d8bad8af9f6ff5cb87c664
    http://security.debian.org/pool/updates/main/o/opensaml2/libsaml2_2.0-2+lenny1_alpha.deb
    Size/MD5 checksum: 1274606 31de8f52a00560f1d20944c80bbf0d22
    http://security.debian.org/pool/updates/main/s/shibboleth-sp2/libshibsp-dev_2.0.dfsg1-4+lenny1_alpha.deb
    Size/MD5 checksum: 39718 fa0a1060a3f753708acab07e93b65a87

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/o/opensaml2/opensaml2-tools_2.0-2+lenny1_amd64.deb
    Size/MD5 checksum: 28296 41e3a07a37cd11363659bc7023d8177c
    http://security.debian.org/pool/updates/main/o/opensaml2/libsaml2_2.0-2+lenny1_amd64.deb
    Size/MD5 checksum: 1191192 50e10dd708890b191da818107c3f096d
    http://security.debian.org/pool/updates/main/s/shibboleth-sp2/libshibsp-dev_2.0.dfsg1-4+lenny1_amd64.deb
    Size/MD5 checksum: 39652 ccaf41767ce12ea968ca6576fce2823c
    http://security.debian.org/pool/updates/main/s/shibboleth-sp2/libshibsp1_2.0.dfsg1-4+lenny1_amd64.deb
    Size/MD5 checksum: 837168 39d5089edf6211e96882f2ae4588b6a8
    http://security.debian.org/pool/updates/main/s/shibboleth-sp2/libapache2-mod-shib2_2.0.dfsg1-4+lenny1_amd64.deb
    Size/MD5 checksum: 228302 ce589d6fb8521b93ab5b9fef89378037
    http://security.debian.org/pool/updates/main/o/opensaml2/libsaml2-dev_2.0-2+lenny1_amd64.deb
    Size/MD5 checksum: 44682 a4d2f8e45f3f661e96d7313bac7656a4

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/o/opensaml2/libsaml2-dev_2.0-2+lenny1_arm.deb
    Size/MD5 checksum: 44896 17ea3c69e9d21e0759e3109c0175913c
    http://security.debian.org/pool/updates/main/s/shibboleth-sp2/libshibsp1_2.0.dfsg1-4+lenny1_arm.deb
    Size/MD5 checksum: 941464 188e5856c70f4d8e08de03e0d91ce366
    http://security.debian.org/pool/updates/main/o/opensaml2/opensaml2-tools_2.0-2+lenny1_arm.deb
    Size/MD5 checksum: 27094 750261b1f04d9e16ce9bbd861059cd96
    http://security.debian.org/pool/updates/main/s/shibboleth-sp2/libshibsp-dev_2.0.dfsg1-4+lenny1_arm.deb
    Size/MD5 checksum: 39952 3221a4f083df6236921972158f491d9c
    http://security.debian.org/pool/updates/main/o/opensaml2/libsaml2_2.0-2+lenny1_arm.deb
    Size/MD5 checksum: 1163622 5369ed1621f18fb85d4703832ad5f231
    http://security.debian.org/pool/updates/main/s/shibboleth-sp2/libapache2-mod-shib2_2.0.dfsg1-4+lenny1_arm.deb
    Size/MD5 checksum: 231604 0e3dc0417fd70c9e6bb5f6aee63c4f0a

    armel architecture (ARM EABI)


    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Krenn
      Sun Jun 7 03:07:26 2026
      from Sydney, Nsw via Telnet
    • Krenn
      Sun Jun 7 01:30:12 2026
      from Sydney, Nsw via Telnet
    • Centurion
      Sat Jun 6 23:27:30 2026
      from Berea, Ohio via Telnet
    • Ab Cadd
      Sat Jun 6 15:42:53 2026
      from Sheboygan, Wi via Telnet
    • Centurion
      Sat Jun 6 15:32:28 2026
      from Berea, Ohio via Telnet
    • Krenn
      Sat Jun 6 11:38:56 2026
      from Sydney, Nsw via Telnet
    • Furryboy
      Sat Jun 6 10:56:29 2026
      from Romania, Galati via SSH
    • Centurion
      Fri Jun 5 22:28:01 2026
      from Berea, Ohio via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (3 / 13)
    Uptime: 157:58:51
    Calls: 12,094
    Calls today: 2
    Files: 15,000
    Messages: 6,517,755

© >>> Magnum BBS <<<, 2026