Bug#987608: shibboleth-sp: Session recovery feature contains a null pointer deference

2021-04-26 Thread Salvatore Bonaccorso
Hi On Tue, Apr 27, 2021 at 08:16:52AM +0200, wf...@debian.org wrote: > Salvatore Bonaccorso writes: > > > MITRE has assigned CVE-2021-31826 for this issue. > > Thanks. I guess you don't want a new security upload for this, but I'll > certainly include it in the changelog of the unstable upload

Bug#987608: shibboleth-sp: Session recovery feature contains a null pointer deference

2021-04-26 Thread wferi
Salvatore Bonaccorso writes: > MITRE has assigned CVE-2021-31826 for this issue. Thanks. I guess you don't want a new security upload for this, but I'll certainly include it in the changelog of the unstable upload. (And in the changelog of the next security upload, whenever that happens.) --

Bug#987608: shibboleth-sp: Session recovery feature contains a null pointer deference

2021-04-26 Thread Salvatore Bonaccorso
Control: retitle -1 shibboleth-sp: CVE-2021-31826: Session recovery feature contains a null pointer deference Hi, On Mon, Apr 26, 2021 at 03:16:14PM +0200, Ferenc W??gner wrote: > Source: shibboleth-sp > Version: 3.0.2+dfsg1-1 > Severity: important > Tags: upstream patch security > Forwarded: ht

Bug#987608: shibboleth-sp: Session recovery feature contains a null pointer deference

2021-04-26 Thread Salvatore Bonaccorso
Hi Ferenc, On Mon, Apr 26, 2021 at 03:16:14PM +0200, Ferenc Wágner wrote: > Source: shibboleth-sp > Version: 3.0.2+dfsg1-1 > Severity: important > Tags: upstream patch security > Forwarded: https://issues.shibboleth.net/jira/browse/SSPCPP-927 > > Shibboleth Service Provider Security Advisory [26

Bug#987608: shibboleth-sp: Session recovery feature contains a null pointer deference

2021-04-26 Thread Ferenc Wágner
Source: shibboleth-sp Version: 3.0.2+dfsg1-1 Severity: important Tags: upstream patch security Forwarded: https://issues.shibboleth.net/jira/browse/SSPCPP-927 Shibboleth Service Provider Security Advisory [26 April 2021] An updated version of the Service Provider software is now available which c