Re: RFC: php-cas (CVE-2022-39369)

2023-06-29 Thread Tobias Frost
Hi, another update time :) Please note that the packages offered below are (still) WIP status and are intended for testing only. php-cas === There is now a potential package for stretch (addressing CVE-2022-39369 and for CVE-2017-171): https://people.debian.org/~tobi/ELTS/php-cas/ (The

Re: RFC: php-cas (CVE-2022-39369)

2023-06-28 Thread Yadd
Hi, I am currently traveling in France, with limited network access, so please excuse me for the delay. I uploaded php-cas a while ago to fix an RC, but I don't have real PHP skills On 6/27/23 23:28, Bastien Roucariès wrote: Le mardi 27 juin 2023, 18:46:25 UTC Tobias Frost a écrit : Hi, ti

Re: RFC: php-cas (CVE-2022-39369)

2023-06-27 Thread Bastien Roucariès
Le mardi 27 juin 2023, 18:46:25 UTC Tobias Frost a écrit : > Hi, > > time for an small update: > > Please note that the packages offered below are WIP status and are intended > for testing only. > > php-cas > === > > I've verified my patched version of php-cas against the apereo CAS > imple

Re: RFC: php-cas (CVE-2022-39369)

2023-06-27 Thread Tobias Frost
Hi, time for an small update: Please note that the packages offered below are WIP status and are intended for testing only. php-cas === I've verified my patched version of php-cas against the apereo CAS implementation and it looks as if it would work :) The package is availble from here: h

Re: RFC: php-cas (CVE-2022-39369)

2023-06-24 Thread Tobias Frost
Hi, (Adding yadd as suggested on IRC, solicating yadd's input as well) Some updates on php-cas: I've continued to work on php-cas to better assess the situation: I've also received information to better assess the serverity of the CVE and now I think this issue should be fixed. (However, I'd lik