-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 31 Jan 2018 15:25:20 +0530 Source: ruby-omniauth Binary: ruby-omniauth Architecture: source all Version: 1.2.1-1+deb8u1 Distribution: jessie-security Urgency: high Maintainer: Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@lists.alioth.debian.org> Changed-By: Pirate Praveen <praveen@debian.org> Description: ruby-omniauth - flexible authentication system utilizing Rack middleware Closes: 888523 Changes: ruby-omniauth (1.2.1-1+deb8u1) jessie-security; urgency=high . * Fix security issue in returning post parameters from session in callback phase (CVE-2017-18076) (Closes: #888523) Checksums-Sha1: 48049ead9b160e0d05e867770490b6259e21afa8 2160 ruby-omniauth_1.2.1-1+deb8u1.dsc 03b73ae540baa254248631c48d345c4e84f06dfb 28163 ruby-omniauth_1.2.1.orig.tar.gz 3989b47011132569d598e08d273d2eaa7b8d1366 3580 ruby-omniauth_1.2.1-1+deb8u1.debian.tar.xz 99c27ab4694fc336a0776c8095d86c90798ae138 17310 ruby-omniauth_1.2.1-1+deb8u1_all.deb Checksums-Sha256: 6b7cadcc597f1639541a709c1c83e5a62966103facf26c18ec77bae71d399c64 2160 ruby-omniauth_1.2.1-1+deb8u1.dsc f9dbc9ebee63e87712e9c91515bbe088d14506fc3a271a89b4ddb2d94001ba65 28163 ruby-omniauth_1.2.1.orig.tar.gz 5e24b3274fec281d2aa96d0680a4fa8158aa1518903aa4c8538e44bef1743c94 3580 ruby-omniauth_1.2.1-1+deb8u1.debian.tar.xz ca8388806482a379322d628e581913a7984d12824f54f1502bad87d95196fc50 17310 ruby-omniauth_1.2.1-1+deb8u1_all.deb Files: eb33d277f49d035b36831f19afeddd14 2160 ruby optional ruby-omniauth_1.2.1-1+deb8u1.dsc 70141fc1b83026c33df6d5711ea29dd3 28163 ruby optional ruby-omniauth_1.2.1.orig.tar.gz 5c57420534adb6b2392d87010a2d7253 3580 ruby optional ruby-omniauth_1.2.1-1+deb8u1.debian.tar.xz 8a7d2593ef1947574b5afe59939f9df0 17310 ruby optional ruby-omniauth_1.2.1-1+deb8u1_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEayzFlnvRveqeWJspbsLe9o/+N3QFAlp9C4AACgkQbsLe9o/+ N3Qsgw//SCu+k11JWJSvrfbF7jLxybtqSI1DwnqEYalM3T8CNzfW8X2PTBE9BIYs ypN94i4vhWSiMvh8RylxhhsCtj2iqxb5CS0sRKaqF3X/5M+RRDvc+9RjOQN6K28M 96vZQHLESTKJxdPz0KQ2yz3v3enzfc4wTcg1s7mctKDVw9FWcHTZZFZoUyEZTuQ6 0nA7AjDQU/vRsfIU4V7I+kTeTGviP82gt2A3XLMc+dsLn+iq9RGgVMLh0HEyZ5eb 9v8Xpzi2nu2cvNBT3oX3P/4mmUdQjmmlP2meoGdRPIcQODYE+YHNrE/Wkk+rd22G OpLRhTs1JFhABq/lKmx0InWr+aC25rJSsRBEjcQ7FxCI79YKyabhS9+Om2WbOzod rCKBjYl5tZ4ri9wE6x9eOxlg+1nNt0Xp3WND2nA1KDVvwoY2cCmtEOOR9aFaGnIJ zj6VOythudiHmqKMIUyv5rujT+4dzmQyla/0XyMhxzQKTODu4PAvqVYth/7wS9lt 4KpEAVzYbn6jqb5JXNSbLhzYnEPFr+t8WNQYN5vtQMCZNfX0AQtPSilOX7vSheNb avk13AkpZX29YDMimqXeeXxMWIlg0xpOjv5jMkceANzq1U1ip2MZlM+pZVffYCfm M0vVzI9nzm96A7KRYMA2Zp7dHfBs5wBGPEoyGMHX5QPeB0ZOuiA= =FpwO -----END PGP SIGNATURE-----