Bug#1088904: simplesamlphp: CVE-2024-52596

2025-05-10 Thread Salvatore Bonaccorso
Hi On Sat, May 10, 2025 at 08:48:56AM +0200, Tobias Frost wrote: > Hi, > > After fixing CVE-2025-27773 (#1100595) for LTS I was taking a look > to tackle unstable as well (as step toward fixing stable9. > While doing this I noticed that the changelog entry for 1.19.7-1+deb12u1 > only mentions CV

Bug#1088904: simplesamlphp: CVE-2024-52596

2025-05-10 Thread Tobias Frost
Hi, After fixing CVE-2025-27773 (#1100595) for LTS I was taking a look to tackle unstable as well (as step toward fixing stable9. While doing this I noticed that the changelog entry for 1.19.7-1+deb12u1 only mentions CVE-2024-52596 but not CVE-2024-52806, and there is also only a patch named CVE-

Bug#1088904: simplesamlphp: CVE-2024-52596

2024-12-02 Thread Salvatore Bonaccorso
Source: simplesamlphp Version: 1.19.7-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: car...@debian.org, Debian Security Team Control: fixed -1 1.19.7-1+deb12u1 Hi Thijs, The following vulnerability was published for simplesamlphp. This bug is just to r