-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 25 Mar 2025 17:13:15 +0100 Source: opensaml Architecture: source Version: 3.2.0-2+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: Debian Shib Team <pkg-shibboleth-devel@alioth-lists.debian.net> Changed-By: Andreas Henriksson <andreas@fatal.se> Closes: 1100464 Changes: opensaml (3.2.0-2+deb11u1) bullseye-security; urgency=high . * Non-maintainer upload by the LTS Security Team. . [ Andreas Henriksson ] * Cherry-pick patch from maintainers debian/bookworm branch to adress TEMP-1100464-F28DDC. . [ Ferenc Wágner ] * New patch: CPPOST-126 - Simple signature verification fails to detect parameter smuggling. Thanks to Scott Cantor (Closes: #1100464) Checksums-Sha1: 8f42f0e2e9af583a608b7bb90cb3089b64ef7c36 2524 opensaml_3.2.0-2+deb11u1.dsc 5d1518a48fe5183bc72b20888533cba59c8e8ae3 589626 opensaml_3.2.0.orig.tar.bz2 09fc220f40dbdf667b1c7fb583859f7d2274576a 19204 opensaml_3.2.0-2+deb11u1.debian.tar.xz 8c86f2657a6c1f6b072a5186d5ccfe709d8e8a7e 7450 opensaml_3.2.0-2+deb11u1_source.buildinfo Checksums-Sha256: b5cbd00f62d15ec3568cfda47523f99c0194b4056c23e2b874d5557be4cee063 2524 opensaml_3.2.0-2+deb11u1.dsc 8c3ba09febcb622f930731f8766e57b3c154987e8807380a4228fbf90e6e1441 589626 opensaml_3.2.0.orig.tar.bz2 32727fa8b944613ccd94d6fdf4de0650e65b4e67a64f50f40768345269fc2fa0 19204 opensaml_3.2.0-2+deb11u1.debian.tar.xz 1f932d704ff18369ffa9f54ea5fe77b152cd6574c50456210b62c30701183afb 7450 opensaml_3.2.0-2+deb11u1_source.buildinfo Files: 0bc3d0c1ddacbc7f6c22903166610979 2524 libs optional opensaml_3.2.0-2+deb11u1.dsc 8f65f24a9b88905c1c335c31dff7b364 589626 libs optional opensaml_3.2.0.orig.tar.bz2 5683b2fd0ffdbe83535b7a3f9e53b9ac 19204 libs optional opensaml_3.2.0-2+deb11u1.debian.tar.xz 3d22bd0a1fb1f3c910ed71057b272280 7450 libs optional opensaml_3.2.0-2+deb11u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE+uHltkZSvnmOJ4zCC8R9xk0TUwYFAmfi13oACgkQC8R9xk0T UwbBgBAAjiDwCdWw95Lxl9TwTtr7XDJj8ChLoUqzSh0ZHACtxa7l+H2EkiprEvQs ZK/53mxjCOcdDdFIlKpscTEYgPyACu6foNpIUk8MG1OT3cJNeG8oN6C1BxbPrS79 a1Eb2ZY9u6EWsG91JkeE72/1lb278ocndy4YusQRQ1m9naK9dSrIoUuODtji9skP +ShmEUQ7wCy/T0H84lZNTbRTLnrgNIklCAsnNW9SJvqrp5ZoZpWlt2B1shnE1f2I m/1UniVIy1P1U2GDys9A3Cs2pkpG3ti+cbwIExChVpuKlNm4CEL07iuANS1b4hcV qV8JFFoQOf95cmzAh5K8YIFjphg8kszGP7RG0+gv0Htcbnr92DYz5MuNRCrTvn26 d2Yzn87pNW+atOVvtwPFJvFcQG3bTmezXOqpEdo7xosEjFOemyRg+K/NsgyCc2kH shrRMelzgX7NILV2GlWulwn/h4+tw6mE9BsCg4bWKPTBBto5QmHskdYFnbSjbANP YIyi7FasQ7K5cgZs131N3OxRpwLV/aNKnCiFxhCypvvwg94zjMoQbJ4gsVdU783X Nvm95Yqyfx6ZMLwgaqgBtSgc98/bYuO0AXIrhWgZHuvQpCiVTeevrlFajZp0OWgU 9XknQInYKfSzME68Vt5QvzWg22mH+oXSAbuawpTwsu3Fedg2l8I= =0shB -----END PGP SIGNATURE-----