UbuntuUpdates.org

Package "liblasso3"

Name: liblasso3

Description:

Library for Liberty Alliance and SAML protocols - runtime library

Latest version: 2.5.1-0ubuntu1.2
Release: bionic (18.04)
Level: updates
Repository: main
Head package: lasso
Homepage: http://lasso.entrouvert.org

Links


Download "liblasso3"


Other versions of "liblasso3" in Bionic

Repository Area Version
base main 2.5.1-0ubuntu1
security main 2.5.1-0ubuntu1.2

Changelog

Version: 2.5.1-0ubuntu1.2 2021-06-02 05:06:23 UTC

  lasso (2.5.1-0ubuntu1.2) bionic-security; urgency=medium

  * SECURITY UPDATE: unsigned assertions after signed valid assertions
    are honored.
    - d/p/CVE-2021-28091.patch: Fix signature checking on unsigned
      response with multiple assertions
    - CVE-2021-28091

 -- Steve Beattie <email address hidden> Fri, 28 May 2021 14:56:48 -0700

Source diff to previous version
CVE-2021-28091 XML signature wrapping vulnerability when parsing SAML responses

Version: 2.5.1-0ubuntu1.1 2019-07-24 17:07:21 UTC

  lasso (2.5.1-0ubuntu1.1) bionic; urgency=high

  * d/p/PAOS-Do-not-populate-Destination-attribute.patch: Do not populate
    "Destination" attribute (LP: #1833299)

 -- Dmitrii Shcherbakov <email address hidden> Thu, 04 Jul 2019 18:42:56 -0500

1833299 lasso includes \



About   -   Send Feedback to @ubuntu_updates