TEMP-1100464-F28DDC

NameTEMP-1100464-F28DDC
DescriptionParameter manipulation allows the forging of signed SAML messages
SourceAutomatically generated temporary name. Not for external reference.
Debian Bugs1100464

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
opensaml (PTS)bullseye3.2.0-2vulnerable
bullseye (security)3.2.0-2+deb11u1fixed
bookworm3.2.1-3vulnerable
bookworm (security)3.2.1-3+deb12u1fixed
sid, trixie3.3.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
opensamlsourcebullseye3.2.0-2+deb11u1
opensamlsourcebookworm3.2.1-3+deb12u1
opensamlsource(unstable)3.3.1-11100464

Notes

https://shibboleth.net/community/advisories/secadv_20250313.txt
https://git.shibboleth.net/view/?p=cpp-opensaml.git;a=commit;h=22a610b322e2178abd03e97cdbc8fb50b45efaee (3.3.1)

Search for package or bug name: Reporting problems