-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 05 Feb 2018 11:14:11 +0530 Source: simplesamlphp Binary: simplesamlphp Architecture: source all Version: 1.9.2-1+deb7u2 Distribution: wheezy-security Urgency: high Maintainer: Thijs Kinkhorst <thijs@debian.org> Changed-By: Abhijith PA <abhijith@disroot.org> Description: simplesamlphp - Authentication and federation application supporting several prot Changes: simplesamlphp (1.9.2-1+deb7u2) wheezy-security; urgency=high . * Non-maintainer upload by the Debian LTS Team. * Fix CVE-2017-18122: Signature validation bypass * Fix CVE-2017-18121: Cross Site Scripting (XSS) in the consentAdmin module * Fix CVE-2018-6521: Use of insecure connection charset (sqlauth module) Checksums-Sha1: d4fbff6b656437e9ae0ea1b50fabf24706cc2415 2087 simplesamlphp_1.9.2-1+deb7u2.dsc d52ed467826fb58e2709ef8d9a2df88d0ce19667 12187 simplesamlphp_1.9.2-1+deb7u2.debian.tar.gz ffa841c6142c13d466b46e2b82d3e77a93e1aa7f 1603266 simplesamlphp_1.9.2-1+deb7u2_all.deb Checksums-Sha256: 9ee4ec3de00ff008b209fa9ff8c7ec73c14bb0a55f514764f120e2838ad8fe22 2087 simplesamlphp_1.9.2-1+deb7u2.dsc 1468d82500756cae84cd0ab0f1522bb82f1f1c357c96f3a6c03f5911a6ae6eb1 12187 simplesamlphp_1.9.2-1+deb7u2.debian.tar.gz 82dc8e1d3cdde889505d21b49aac25bc5c64e3581dac09bdaee35789c9e937eb 1603266 simplesamlphp_1.9.2-1+deb7u2_all.deb Files: c7a597cf36fadfba4dbf55a333579539 2087 web extra simplesamlphp_1.9.2-1+deb7u2.dsc e218237f2fa15b18d1d7d1bd2c2891df 12187 web extra simplesamlphp_1.9.2-1+deb7u2.debian.tar.gz 96da2c84e9512026966bfb3934521f2a 1603266 web extra simplesamlphp_1.9.2-1+deb7u2_all.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlp8lE5fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1Hklz4P/ipGq6LSz9+ZmS1pcnPikthHMqaQMAMqSvPy eOU40LtjbUCli1OVND63qqz98OvaSHzUQzenegt+Z6Cul4iDs1QFir34sHfzLRr9 kjXhjONWAb6uEJver+OeFgeuy9SdOnfzyDsFTbGCr0duyY2P89ALAQRnQiFz0Vu5 5FejQTfvTRedVOjg5UFQyZrx0vum/oyBVL7DAcr1DgVx8N8/s/FIOJUubJQc+HL5 ZS9C3Nhfq5UgLXocZmnIF7gAZCoTkUJ0IpW6Y+0juydK7On7qk5ttq7blMo+bILB 4pc8TlaN6EUobGV1rOJUFSMV6eGAaTKibFOmkmlDSIfsHPo/1GueIysrT2bK4f8R 1aZzLlWoKTDyVOdOkuDSM9Atq5jHL8IXBlHfbWY+N1rFm37oM/PxAOLo2ZIOZYvT GAQYUviHLIpmh0/BY0K0X37PRKX3TBSRO4/R8VuL2lsd6ZuBDcLyhmtXc9emhrQ5 7EFGo0uGz8VrPizm7kKkqFzCJSe1T8EcRX0p/pOF1QNctcoA5C+ujILwDxmIeuMl 9t7g5rHYK9Vd+mIa7R9Ewc+7nd75Xm+xnh2Eo7e9CvlS3zT1j6Ma3IFh9O4kzldl x/loJ+9+HJA5oZtadThsLPwXjMPzauk2XL8p6mH1HreI3zSU9BtdcO755TeGYTzg O3ajWfVo =8pwn -----END PGP SIGNATURE-----