UbuntuUpdates.org

Package "python3-pysaml2"

Name: python3-pysaml2

Description:

SAML Version 2 to be used in a WSGI environment - Python 3.x

Latest version: 4.9.0-0ubuntu3.1
Release: focal (20.04)
Level: security
Repository: main
Head package: python-pysaml2
Homepage: https://github.com/rohe/pysaml2

Links


Download "python3-pysaml2"


Other versions of "python3-pysaml2" in Focal

Repository Area Version
base main 4.9.0-0ubuntu3
updates main 4.9.0-0ubuntu3.1

Changelog

Version: 4.9.0-0ubuntu3.1 2021-09-08 13:06:50 UTC

  python-pysaml2 (4.9.0-0ubuntu3.1) focal-security; urgency=medium

  * SECURITY UPDATE: improper verification of cryptographic signature
    - debian/patches/CVE-2021-21239.patch: restrict the key data that
      xmlsec1 accepts to only x509 certs in src/saml2/sigver.py,
      tests/test_xmlsec1_key_data.py,
      tests/xmlsec1-keydata/signed-assertion-random-embedded-cert.xml,
      tests/xmlsec1-keydata/signed-assertion-with-hmac.xml,
      tests/xmlsec1-keydata/signed-response-with-hmac.xml.
    - CVE-2021-21239

 -- Marc Deslauriers <email address hidden> Tue, 22 Jun 2021 11:06:36 -0400

CVE-2021-21239 PySAML2 is a pure python implementation of SAML Version 2 Standard. PySAML2 before 6.5.0 has an improper verification of cryptographic signature vuln



About   -   Send Feedback to @ubuntu_updates