Hash: SHA512

Package        : opensaml2
Version        : 2.4.3-4+deb7u2
CVE ID         : CVE-2017-16853
Debian Bug     : 881856

Rod Widdowson of Steading System Software LLP discovered a coding error
in the OpenSAML library, causing the DynamicMetadataProvider class to
fail configuring itself with the filters provided and omitting whatever
checks they are intended to perform.

For Debian 7 "Wheezy", these problems have been fixed in version
2.4.3-4+deb7u2.

We recommend that you upgrade your opensaml2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-1178-1: opensaml2 security update

November 18, 2017
Rod Widdowson of Steading System Software LLP discovered a coding error in the OpenSAML library, causing the DynamicMetadataProvider class to fail configuring itself with the filte...

Summary

For Debian 7 "Wheezy", these problems have been fixed in version
2.4.3-4+deb7u2.

We recommend that you upgrade your opensaml2 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : opensaml2
Version : 2.4.3-4+deb7u2
CVE ID : CVE-2017-16853
Debian Bug : 881856

Related News