[Bug 1732606] Re: Shibboleth Service Provider Security Advisory [15 November 2017]

2017-11-16 Thread Guy Halse
The patch proposed by the Shibboleth developers is simple enough and would appear to apply to earlier versions. Indeed, the bug has already been patched in Debian stretch (2.6.0+dfsg1-4+deb9u1) and jessie (2.5.3+dfsg-2+deb8u1) which appear to be the original packages from which these derive. The De

[Bug 1732606] Re: Shibboleth Service Provider Security Advisory [15 November 2017]

2017-11-16 Thread Steve Beattie
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is availabl

[Bug 1732606] Re: Shibboleth Service Provider Security Advisory [15 November 2017]

2017-11-15 Thread Guy Halse
The advisory is already public, so there's no benefit in keeping this bug report private. ** Also affects: opensaml2 (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.lau