\{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2021:4325', 'synopsis': 'Moderate: lasso security and enhancement update', 'severity': 'Moderate', 'topic': 'An update for lasso is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': 'The lasso packages provide the Lasso library that implements the Liberty Alliance Single Sign-On standards, including the SAML and SAML2 specifications. It allows handling of the whole life-cycle of SAML-based federations and provides bindings for multiple languages.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\nAdditional Changes:\nFor detailed information on changes in this release, see the Rocky Linux 8.5 Release Notes linked from the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['1829785', '1940089'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-28091.json:::CVE-2021-28091'], 'references': [], 'publishedAt': '2021-11-15T07:24:20.139691Z', 'rpms': ['lasso-2.6.0-12.el8.aarch64.rpm', 'lasso-2.6.0-12.el8.i686.rpm', 'lasso-2.6.0-12.el8.src.rpm', 'lasso-2.6.0-12.el8.x86_64.rpm', 'lasso-debuginfo-2.6.0-12.el8.aarch64.rpm', 'lasso-debuginfo-2.6.0-12.el8.i686.rpm', 'lasso-debuginfo-2.6.0-12.el8.x86_64.rpm', 'lasso-debugsource-2.6.0-12.el8.aarch64.rpm', 'lasso-debugsource-2.6.0-12.el8.i686.rpm', 'lasso-debugsource-2.6.0-12.el8.x86_64.rpm', 'lasso-devel-2.6.0-12.el8.aarch64.rpm', 'lasso-devel-2.6.0-12.el8.i686.rpm', 'lasso-devel-2.6.0-12.el8.x86_64.rpm']}\

Rocky Linux: RLSA-2021:4325 lasso security and enhancement update

September 2, 2022
An update for lasso is now available for Rocky Linux 8. Rocky Linux Product Security has rated this update as having a security impact of Moderate

Summary

An update for lasso is now available for Rocky Linux 8. Rocky Linux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.


The lasso packages provide the Lasso library that implements the Liberty Alliance Single Sign-On standards, including the SAML and SAML2 specifications. It allows handling of the whole life-cycle of SAML-based federations and provides bindings for multiple languages. For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Rocky Linux 8.5 Release Notes linked from the References section.

RPMs

lasso-2.6.0-12.el8.aarch64.rpm

lasso-2.6.0-12.el8.i686.rpm

lasso-2.6.0-12.el8.src.rpm

lasso-2.6.0-12.el8.x86_64.rpm

lasso-debuginfo-2.6.0-12.el8.aarch64.rpm

lasso-debuginfo-2.6.0-12.el8.i686.rpm

lasso-debuginfo-2.6.0-12.el8.x86_64.rpm

lasso-debugsource-2.6.0-12.el8.aarch64.rpm

lasso-debugsource-2.6.0-12.el8.i686.rpm

lasso-debugsource-2.6.0-12.el8.x86_64.rpm

lasso-devel-2.6.0-12.el8.aarch64.rpm

lasso-devel-2.6.0-12.el8.i686.rpm

lasso-devel-2.6.0-12.el8.x86_64.rpm

References

No References

CVEs

https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-28091.json

Severity
Name: RLSA-2021:4325
Affected Products: Rocky Linux 8

Fixes

https://bugzilla.redhat.com/show_bug.cgi?id=

https://bugzilla.redhat.com/show_bug.cgi?id=


Related News