-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 16 Apr 2025 11:13:22 +0200 Source: libapache2-mod-auth-openidc Architecture: source Version: 2.4.9.4-0+deb11u5 Distribution: bullseye-security Urgency: high Maintainer: Moritz Schlarb <schlarbm@uni-mainz.de> Changed-By: Moritz Schlarb <moschlar@debian.org> Closes: 1102413 Changes: libapache2-mod-auth-openidc (2.4.9.4-0+deb11u5) bullseye-security; urgency=high . * Fix CVE-2025-31492 "protected content leakage when using OIDCProviderAuthRequestMethod POST" Backported applicable portions from upstream fix in https://github.com/OpenIDC/mod_auth_openidc/commit/b59b8ad63411857090ba1088e23fe414c690c127 (Closes: #1102413) Checksums-Sha1: 305b458b33d1ed6425ba64861135cc4a349f7acb 2556 libapache2-mod-auth-openidc_2.4.9.4-0+deb11u5.dsc 47f8b949552c3d32f019c5cf785c4672dc0f8aae 261544 libapache2-mod-auth-openidc_2.4.9.4.orig.tar.gz 431e8ba719e3f49a855740f809b17ffbde28d8a7 9172 libapache2-mod-auth-openidc_2.4.9.4-0+deb11u5.debian.tar.xz 208075e8b8c53577fc23d176a2101f1e056dc0b6 8784 libapache2-mod-auth-openidc_2.4.9.4-0+deb11u5_amd64.buildinfo Checksums-Sha256: bb3c8e10af483c59cf7a61a57eb45e81f1c340ee2eb518bc36287e61bf92f42c 2556 libapache2-mod-auth-openidc_2.4.9.4-0+deb11u5.dsc 142ee7abd49a4c6e2a7233c9124143709e733e8e51896c4a4f4172b0ffbc4741 261544 libapache2-mod-auth-openidc_2.4.9.4.orig.tar.gz 145496088cdfae0e6813f8f5c0454df86e533325ac71d44b33514339068f8530 9172 libapache2-mod-auth-openidc_2.4.9.4-0+deb11u5.debian.tar.xz 941ee0f6683d5058479237dc64935b160e03653a3b6da6e90e767cf61500f634 8784 libapache2-mod-auth-openidc_2.4.9.4-0+deb11u5_amd64.buildinfo Files: 94db93e437066f5af98d4a6175cb46b2 2556 httpd optional libapache2-mod-auth-openidc_2.4.9.4-0+deb11u5.dsc 21959e96f73545012afec7201f5f46fd 261544 httpd optional libapache2-mod-auth-openidc_2.4.9.4.orig.tar.gz 6463479e76890373274206c0642f5dc2 9172 httpd optional libapache2-mod-auth-openidc_2.4.9.4-0+deb11u5.debian.tar.xz c507a5a450226c3d197fb60a23ffc59c 8784 httpd optional libapache2-mod-auth-openidc_2.4.9.4-0+deb11u5_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQJIBAEBCgAyFiEE3wEiR7/GVQGv8oRFDCS4Qcfduq8FAmgAu/EUHG1vc2NobGFy QGRlYmlhbi5vcmcACgkQDCS4Qcfduq/gqxAAkQnrwnR018PD0AFiF9seaip2d97R Rgv0VW6FSpKkqeqDP6cWPhmw6L/2FK+EjMGnEgZRX47tB0rOnRdpxFSzoIo+gw/D S73hQALsEcds+z7fgxGLqkb9FZQMXwd/uGStRVUEFBzdwQ+OjNe6FmIV0yqm90EA tc2dQv84G8c6T7+ktt//889EDvqkCuJIUsBLmdfFond7wtcQUCkVrM14SPOtTF5z AQt0FveBKa7wHjld2e+uD7Ubwdfr5gU0Sxp8orT+6yXERhT4BSXz9XhwNheHME0t YSO3SrKhfTsKcXIKmwccACer9nzUdVITDjuWpdQKxAFt3iSjB0T2UgG8YzqdhYoH ZhYZeoUXaHJ+otWf7D6AAEKKKxuZPdl+2oYQQwzwRC00gUSeEXb0NzJbejV6NazR Oy8/hpPmB+0FdpEvm43XZIdApAcKQSZgwRKTqAK1d1g6b9TMJv8x2v/KtbWhNWK5 pLULP+BRamSQ2OlkCVu9tDTKroE8qHDzfBj01M04veUqn5kxrUHCOgKzX7m/fWtZ PFoJXXUyielI9UZUNPvG5tAEYbZxEB0j0UogQpulvPyCOnOeoTjbu3sUuH3mdao/ c1YaoM3TiHRUcJrCwNJuvuGMKBgWSzy6XJOZH8EUEN+pABsxzJvSLBCFFFUoBHKm 8yULHqsRDgKz2sw= =jy39 -----END PGP SIGNATURE-----