• Bug#1100595: marked as done (simplesamlphp: CVE-2025-27773) (2/2)

    From Debian Bug Tracking System@1:229/2 to All on Sat May 31 23:40:02 2025
    [continued from previous message]

    KTwmuM/zlNFT/E/YAdqvRlqJIstMMhqHQd6xQvN0Y1hojCm9RBxqkDy62DU9tlDRa/1uFHjjCvW3r
    tP3fwFB35YFSgMqim+b7GKYdcgXJARwXRWpxPbgGuQh4ykMASrCytwKtv21BM/8bnt1UKss9qT/Ag
    HC+cDAWh9fQ3HfVRsrdKmQYeJAib8Tvy/44SymDOF9STgIlGP0OSUmsqDeBX/iI9xR0k8nXDjFFd6
    54RHjmwg==;
    Received: from dak by fasolo.debian.org with local (Exim 4.94.2)
    (envelope-from <envelope@ftp-master.debian.org>)
    id 1uLToQ-000yzv-1h; Sat, 31 May 2025 21:32:18 +0000
    From: Debian FTP Masters <ftpmaster@ftp-master.debian.org>
    Reply-To: Tobias Frost <tobi@debian.org>
    To: 1100595-close@bugs.debian.org
    X-DAK: dak process-policy
    X-Debian: DAK
    X-Debian-Package: simplesamlphp
    Debian: DAK
    Debian-Changes: simplesamlphp_1.19.7-1+deb12u2_source.changes
    Debian-Source: simplesamlphp
    Debian-Version: 1.19.7-1+deb12u2
    Debian-Architecture: source
    Debian-Suite: proposed-updates
    Debian-Archive-Action: accept
    MIME-Version: 1.0
    Subject: Bug#1100595: fixed in simplesamlphp 1.19.7-1+deb12u2
    Content-Type: multipart/signed; micalg="pgp-sha256";
    protocol="application/pgp-signature";
    boundary="===============0127389172668689464=="
    Message-Id: <E1uLToQ-000yzv-1h@fasolo.debian.org>
    Date: Sat, 31 May 2025 21:32:18 +0000

    --===============0127389172668689464==
    Content-Type: text/plain; charset="utf-8"
    Content-Transfer-Encoding: quoted-printable

    Source: simplesamlphp
    Source-Version: 1.19.7-1+deb12u2
    Done: Tobias Frost <tobi@debian.org>

    We believe that the bug you reported is fixed in the latest version of simplesamlphp, which is due to be installed in the Debian FTP archive.

    A summary of the changes between this version and the previous one is
    attached.

    Thank you for reporting the bug, which will now be closed. If you
    have further comments please address them to 1100595@bugs.debian.org,
    and the maintainer will reopen the bug report if appropriate.

    Debian distribution maintenance software
    pp.
    Tobias Frost <tobi@debian.org> (supplier of updated simplesamlphp package)

    (This message was generated automatically at their request; if you
    believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org)


    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    Format: 1.8
    Date: Sun, 11 May 2025 08:35:04 +0200
    Source: simplesamlphp
    Architecture: source
    Version: 1.19.7-1+deb12u2
    Distribution: bookworm
    Urgency: medium
    Maintainer: Thijs Kinkhorst <thijs@debian.org>
    Changed-By: Tobias Frost <tobi@debian.org>
    Closes: 1100595
    Changes:
    simplesamlphp (1.19.7-1+deb12u2) bookworm; urgency=medium
    .
    * Team upload for stable proposed updates.
    * Fix CVE-2025-27773 (Closes: #1100595)
    Checksums-Sha1:
    ca31c17670fb5b519bb533af1b08a9f4459e144c 1913 simplesamlphp_1.19.7-1+deb12u2.dsc
    9ff667a9d791fe41fec46062f213919544379db4 2784732 simplesamlphp_1.19.7-1+deb12u2.debian.tar.xz
    d005d81484ce2da966b7edb9901ba91716e6e9f8 6043 simplesamlphp_1.19.7-1+deb12u2_amd64.buildinfo
    Checksums-Sha256:
    3b04ada4ffe389ef3acb79d6d4b5d135318c285d2beed9f0bfad787e84bb687c 1913 simplesamlphp_1.19.7-1+deb12u2.dsc
    0135f36a95d025abda7c2fbf75a9f2a501fbfd968f687d90c6b42f1b63a14b21 2784732 simplesamlphp_1.19.7-1+deb12u2.debian.tar.xz
    eb0967f156b26e19ac52d33e2137e7d7afccdf172808c3e00a692eabe108850b 6043 simplesamlphp_1.19.7-1+deb12u2_amd64.buildinfo
    Files:
    5ee8701266adb4283040ee776e324730 1913 web optional simplesamlphp_1.19.7-1+deb12u2.dsc
    f61eca622cbb06237e666aeee66c1fbd 2784732 web optional simplesamlphp_1.19.7-1+deb12u2.debian.tar.xz
    d5ebfd25ef07fc4a3db4c99fd5ed8cf6 6043 web optional simplesamlphp_1.19.7-1+deb12u2_amd64.buildinfo

    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEE/d0M/zhkJ3YwohhskWT6HRe9XTYFAmggrx8ACgkQkWT6HRe9 XTYVrg//dXv7GVrg0hyz/VxAqb7FqJ4bx4Sp1+0eVH9fQLJtU02ABmPQf0RfeUpD la7MzoRT6jieY8/XHP0a1fvs/Zad5YxqqKxpkAVsvXGgtJA00Imk3N+NEiHtfZ49 loyxfS6hwepO/sI8yIuZJ9IKOo746c8yxr5B2zki7RVErKQ3RYEGwtwCBQz1vfDQ ixLf7Jz5YDDF6j4WS0uPPGba7M9bxYpBUe361qjHtDBYmPdBIAP/9Bn7q+5cetdv /edThhD3SL3haGItWsyHeMEX37w41LHuQd/ODCRkHtrc2jKZRi2vJOoGi79nEEMj iqDnye/zRkx8fBaYRrMGEIWPvkzxBNrEULaURpA0y0E725jMk9avDuXGXBtetDQ7 Syi/EYnEZrp6lOrhpxg3XYhpPM5Cm/7m6Hu8jN395qbPXq8XiAO52+Ib+Nih/5bA eRHtRawwB1oeA86SinCuhXM0ze/cww4nxG5YzyoVUJ5uLc4ERk52XWFvk8dPtZ6m Wo1+YxlvCUbASAJBTtUrO7+/HQg5AXvKTcyZUutShhRRwS+rmYPeLo28SDkaKrK7 bK3FxXNgx/xZYtu8TzeIyZ5dwGwSCe+Dgtw/Qt8mcI8iRNxO6MSk1LybNN6uZBgF FVEqfukbywjcQtT++/MC9uWXv61QbwQgUpXZ8TW09rorBfANvlA=
    =MYQi
    -----END PGP SIGNATURE-----


    --==============@27389172668689464=Content-Type: application/pgp-signature

    -----BEGIN PGP SIGNATURE-----

    iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCaDt1YgAKCRCb9qggYcy5 IXRmAP9+ZRnGfA4pVqhNJEHQ37H/lO8LTlUaqeoIPh8OIPgDmQD/Rxrr2r5I1Nzm 8mVAAGjcy3qI5rPM+hXRUcNorre7fgE=s4oz
    -----END PGP SIGNATURE-----

    --==============@27389172668689464==--

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)