Name Status Last Modified Last Commit
lp:debian/wheezy/xmltooling 1 Development 2015-07-27 11:39:26 UTC
17. Apply security fix from 1.5.5 for CVE...

Author: Ferenc Wágner
Revision Date: 2015-07-27 11:39:26 UTC

Apply security fix from 1.5.5 for CVE-2015-0851 DoS (Closes: #793855):
Shibboleth SP software crashes on well-formed but invalid XML

lp:debian/jessie/xmltooling 1 Development 2015-07-19 19:06:38 UTC
18. Apply security fix from 1.5.5 for CVE...

Author: Ferenc Wágner
Revision Date: 2015-07-19 19:06:38 UTC

Apply security fix from 1.5.5 for CVE-2015-0851 DoS (Closes: #793855):
Shibboleth SP software crashes on well-formed but invalid XML

lp:debian/xmltooling 1 Development 2015-07-12 19:18:55 UTC
18. * Non maintainer upload. * Call cpp w...

Author: Matthias Klose
Revision Date: 2015-07-12 19:18:55 UTC

* Non maintainer upload.
* Call cpp with -P for the boost config. Closes: #778185.

lp:debian/stretch/xmltooling 1 Development 2015-07-12 19:18:55 UTC
18. * Non maintainer upload. * Call cpp w...

Author: Matthias Klose
Revision Date: 2015-07-12 19:18:55 UTC

* Non maintainer upload.
* Call cpp with -P for the boost config. Closes: #778185.

lp:debian/experimental/xmltooling 1 Development 2013-06-18 14:18:20 UTC
18. * New upstream release. - Update xm...

Author: Russ Allbery
Revision Date: 2013-06-18 14:18:20 UTC

* New upstream release.
  - Update xmlsig 1.1 schema to final CR
  - Check for missing private key in configuration check
* Move single-debian-patch to local-options and patch-header to
  local-patch-header so that they only apply to the packages built from
  the canonical Git repository and NMUs get regular version-numbered
  patches.
* Switch to xz compression for *.debian.tar and the *.deb packages.
* Fix some minor debian/copyright inaccuracies and a missing GPL-3
  pointer introduced in the previous release.

lp:debian/squeeze/xmltooling 1 Development 2010-05-13 10:03:36 UTC
9. * Force source format 1.0 for now sin...

Author: Russ Allbery
Revision Date: 2010-05-13 10:03:36 UTC

* Force source format 1.0 for now since it makes backporting easier.
* Add ${misc:Depends} to all package dependencies.
* Update standards version to 3.8.4 (no changes required).

lp:debian/lenny/xmltooling 2 Mature 2009-09-22 19:23:54 UTC
3. * SECURITY: Certificate subject names...

Author: Russ Allbery
Revision Date: 2009-09-22 19:23:54 UTC

* SECURITY: Certificate subject names were incorrectly matched against
  trusted "key names" when they contained nul characters. This affects
  only Shibboleth deployments relying on the "PKIX" style of trust
  validation, used in the absence of explicit certificate information in
  the SAML metadata provided to the SP and reliance on certificate
  authorities found in the <KeyAuthority> metadata extension element.
  See <http://shibboleth.internet2.edu/secadv/secadv_20090817.txt>
* SECURITY: Correctly handle decoding of malformed URLs, closing a
  possibly exploitable buffer overflow.
  See <http://shibboleth.internet2.edu/secadv/secadv_20090826.txt>
* SECURITY: Correctly honor the "use" attribute of <KeyDescriptor> SAML
  metadata to honor restrictions to signing or encryption. This is a
  partial fix; the complete fix also requires a new version of the
  OpenSAML library.
  See <http://shibboleth.internet2.edu/secadv/secadv_20090817a.txt>

17 of 7 results