-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 02 Feb 2021 08:42:57 +1100 Source: python-pysaml2 Binary: python-pysaml2 python3-pysaml2 python-pysaml2-doc Architecture: source Version: 3.0.0-5+deb9u2 Distribution: stretch-security Urgency: medium Maintainer: PKG OpenStack <openstack-devel@lists.alioth.debian.org> Changed-By: Brian May <bam@debian.org> Description: python-pysaml2 - SAML Version 2 to be used in a WSGI environment - Python 2.x python-pysaml2-doc - SAML Version 2 to be used in a WSGI environment - doc python3-pysaml2 - SAML Version 2 to be used in a WSGI environment - Python 3.x Changes: python-pysaml2 (3.0.0-5+deb9u2) stretch-security; urgency=medium . [ Brian May ] * Non-maintainer upload by the LTS Security Team. * Fix CVE-2021-21239 - Restrict the key data that xmlsec1 accepts to on. . [ Abhijith PA ] * Fix CVE-2017-1000433 - bypass password with python optimizations enabled Checksums-Sha1: db753cca7fbf9de4b0f0ccd3aa4155b3ccb31d13 2854 python-pysaml2_3.0.0-5+deb9u2.dsc 7f0f5cbe86dc884ef8ad8d20a5b66cd69b0210a8 16128 python-pysaml2_3.0.0-5+deb9u2.debian.tar.xz 98a1898a3185a79a46448185b30c49f77650fb1e 10123 python-pysaml2_3.0.0-5+deb9u2_amd64.buildinfo Checksums-Sha256: de4f1f78f4f1967c36e0efc8c18662b587160d0a5755b3965d0ee4eb038ba750 2854 python-pysaml2_3.0.0-5+deb9u2.dsc 29e14aad8a477bc272448f1cd4914ff23f5535e6a775008aa65310b709eb3773 16128 python-pysaml2_3.0.0-5+deb9u2.debian.tar.xz 63f1240be39d20fac72d4cb4ac2550921c655134bf659b2aa36de309d09cf46c 10123 python-pysaml2_3.0.0-5+deb9u2_amd64.buildinfo Files: 0cfb0cd19b05fd3627a49d473963d5b3 2854 python optional python-pysaml2_3.0.0-5+deb9u2.dsc 99e9a7292af39cd7c7850e1e3afdb7d9 16128 python optional python-pysaml2_3.0.0-5+deb9u2.debian.tar.xz da1062c2f48388cdaf0c1e72e16d15e7 10123 python optional python-pysaml2_3.0.0-5+deb9u2_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCgAyFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmA3+OMUHGFiaGlqaXRo QGRlYmlhbi5vcmcACgkQhj1N8u2cKO81cQ/+OZKJtK6/VZ8yc+VjI6514XYRGsNf 48Tzvle7nmjjYSJQSP3zbWje/mfvMSldTw1SytBuKTBYI4aO10JH2qJLtY+UuGyt 57/+zGOkvGszXrdHUHuPdbk6pvUUyn6IEwJRqxLuZmihQN2hsVclmgf49GFsg9Sl rLZN5wR/HmVhOUd6MKtJkd90gPOs5UwA7YR/F+lk6k5x5lLrIxKiinwKk3uB8ORJ Iq23m5BHZYN0e1JbzCpEASwCPvPTSBlzCnB+vfEXhk2tEFASYAhjjb50rBJGPAX4 H7zay4R58skl5kmyruST1ldKfl4lMcJo38C0kVViii6JkNZWKlYL/wFiYj+OhDRA 8geu/6kQvco/1iYZ3BE2jZkWHa9B05CSIUf0e0KH5iOZP9tpf9cOAaissOAuKjkZ dVvYMaCd7GBUnIgjGanAd/U3TRYWPyZD4OIvkp9r+/2nMK869w4M7InuIVrc/yk1 0aielU4Oqto5M3fOrdKVoJbQ92Sm5w7Do9O9c4P/+Uj9gpZDs5ZpKwq0pf0UR5Iq LwXpfSoluNeZBfdK08QQJhvMhegGqALgirFh/FpgtcNtJD+nQKWlF3Nb1xMtXV62 jYfTrOrQBkKzDjIJ+9ogJpdbpIAryBE3Zd+TaE0Fa+ZdTGFvF51ej1R5KlWu6E1s b2xNK+QTbOZcu4I= =PAiE -----END PGP SIGNATURE-----