-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3612-1 [email protected] https://www.debian.org/lts/security/ Yadd October 08, 2023 https://wiki.debian.org/LTS - -------------------------------------------------------------------------
Package : lemonldap-ng Version : 2.0.2+ds-7+deb10u10 CVE ID : CVE-2023-44469 Two vulnerabilities were discovered in lemonldap-ng: * an open redirection when OpenID-Connect configuration isn't generated by the manager and if OIDC RP has no oidcRPMetaDataOptionsRedirectUris * a Server-Side-Request-Forgery in OpenID-Connect (CVE-2023-44469) For Debian 10 buster, this problem has been fixed in version 2.0.2+ds-7+deb10u10. We recommend that you upgrade your lemonldap-ng packages. For the detailed security status of lemonldap-ng please refer to its security tracker page at: https://security-tracker.debian.org/tracker/lemonldap-ng Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmUi3MkACgkQ9tdMp8mZ 7unLZg/9FXibZiyXXE/fc+BtRtm3cKyFkYE0BLaCzFTnudaXWaPzE5DH7sGUbPyR Sa4sBq/MuNLTNu9hU0sPBfT4fxklKVsJ86fjydLKCxzkMikYCItBHoI7pqtdyE8T po/X0jhIDwi1ANd0j4rMkSif483o4kX8RFKkxi9gxCNf0C0gu1SJvV4Kkvl7qrdT d5APfBh6iUswPfDrXfmtKO//hDRPELDo2SZwkW0P8rW+R2mNeAowYT9xO0iQDBUr F7gz9Q7aEM29li8+Yo/qX04deHHjijKuLrMTYiT/wjIkR0EWseT2r6cQW8R6e04Z FYPx7ScO/FpDGEfJN3xUmLCwJTTyfXgugHis5K5UNp699bOdFLFAxS+h7bp9xC0P RdZwzq+FQRt6mPrazgBuTVsHgKkgpYHyRWz4XP472O06pJCUfrvp4n6PVUeWBkMZ M9C0UA7wI3dsHbPWp5gFkTFHK7m9vwAeemGXhVwofJmxhztzkuZneo92GKra+rz4 UHZXcZ2cVJjsHUZjVEhjtfeRfYPi8OHlpc+uI+DDEYI5KuQfarga38RTdwZZNseJ 42xFAfOlrGChoDPZW100G4ZpMb2LJwDXOvd9CQA/p2XJ+Qvw2X2f6Xzpphf/9SKI PIg5rI2r1n1UxysxYDV3Ucr3raDIdQzpsrOQGLo+EOeQgT78ANQ= =KleU -----END PGP SIGNATURE-----
