Re: Bug#1104484: libapache2-mod-auth-openidc: CVE-2025-3891

2025-05-07 Thread Sylvain Beucler
Hi again Moritz, On 07/05/2025 19:15, Sylvain Beucler wrote: On 07/05/2025 14:56, Roberto C. Sánchez wrote: On Wed, May 07, 2025 at 02:46:04PM +0200, Moritz Schlarb wrote: On Wed, 2025-05-07 at 10:59 +, Moritz Mühlenhoff wrote: So RedHat has provided more information and we know it's fixe

Re: Bug#1104484: libapache2-mod-auth-openidc: CVE-2025-3891

2025-05-07 Thread Sylvain Beucler
Hi, On 07/05/2025 14:56, Roberto C. Sánchez wrote: On Wed, May 07, 2025 at 02:46:04PM +0200, Moritz Schlarb wrote: On Wed, 2025-05-07 at 10:59 +, Moritz Mühlenhoff wrote: So RedHat has provided more information and we know it's fixed by https://github.com/OpenIDC/mod_auth_openidc/commit/29

Re: Bug#1104484: libapache2-mod-auth-openidc: CVE-2025-3891

2025-05-07 Thread Roberto C . Sánchez
Hi Moritz, On Wed, May 07, 2025 at 02:46:04PM +0200, Moritz Schlarb wrote: > Dear LTS Team. > > On Wed, 2025-05-07 at 10:59 +, Moritz Mühlenhoff wrote: > > > > > > So RedHat has provided more information and we know it's fixed by > > > https://github.com/OpenIDC/mod_auth_openidc/commit/29ea7

Re: Bug#1104484: libapache2-mod-auth-openidc: CVE-2025-3891

2025-05-07 Thread Moritz Schlarb
package and claiming and issuing the DLA, right? [1]: https://lts-team.pages.debian.net/wiki/Development.html Regards, Moritz diff -Nru libapache2-mod-auth-openidc-2.4.9.4/debian/changelog libapache2-mod-auth-openidc-2.4.9.4/debian/changelog --- libapache2-mod-auth-openidc-2.4.9.4/debian/changelo

Re: Bug#1102413: libapache2-mod-auth-openidc: CVE-2025-31492

2025-04-17 Thread Moritz Schlarb
Hey Sylvain, On Wed, 2025-04-16 at 12:40 +0200, Sylvain Beucler wrote: > The patch looks good :) Thanks! > The LTS upload workflow is detailed at: > https://lts-team.pages.debian.net/wiki/Development.html > > As a DD you can do everything by yourself, but if you want I can take > care of the a

Re: Bug#1102413: libapache2-mod-auth-openidc: CVE-2025-31492

2025-04-16 Thread Sylvain Beucler
lease advise me how to continue, since this is my first security fix in LTS land. ;) Thanks, Moritz On Tue, 2025-04-08 at 22:05 +0200, Salvatore Bonaccorso wrote: Source: libapache2-mod-auth-openidc Version: 2.4.16.10-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbu

Re: Bug#1102413: libapache2-mod-auth-openidc: CVE-2025-31492

2025-04-16 Thread Moritz Schlarb
, Moritz On Tue, 2025-04-08 at 22:05 +0200, Salvatore Bonaccorso wrote: > Source: libapache2-mod-auth-openidc > Version: 2.4.16.10-1 > Severity: grave > Tags: security upstream > Justification: user security hole > X-Debbugs-Cc: car...@debian.org, Debian Security Team > >

Re: libapache2-mod-auth-openidc

2019-11-20 Thread Mike Gabriel
On Mi 20 Nov 2019 17:52:11 CET, Markus Koschany wrote: Hi, Am 20.11.19 um 17:13 schrieb Abhijith PA: Hello Markus, There isn't any open vulnerabilities in libapache2-mod-auth-openidc. Last one was announced in DLA-1996-1. Any particular reason for keeping it in dla-needed.txt. I

Re: libapache2-mod-auth-openidc

2019-11-20 Thread Markus Koschany
Hi, Am 20.11.19 um 17:13 schrieb Abhijith PA: > Hello Markus, > > There isn't any open vulnerabilities in libapache2-mod-auth-openidc. > Last one was announced in DLA-1996-1. Any particular reason for keeping > it in dla-needed.txt. It was automatically removed from d

libapache2-mod-auth-openidc

2019-11-20 Thread Abhijith PA
Hello Markus, There isn't any open vulnerabilities in libapache2-mod-auth-openidc. Last one was announced in DLA-1996-1. Any particular reason for keeping it in dla-needed.txt. --abhijith