Summary: | <dev-python/pysaml2-4.6.5-r1: does not check that the signature in a SAML document is enveloped (CVE-2020-5390) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | GLSAMaker/CVETool Bot <glsamaker> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | openstack, prometheanfire |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B4 [noglsa cve] | ||
Package list: | Runtime testing required: | --- |
Description
GLSAMaker/CVETool Bot
![]() The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=fb6782d4bdfaedc803fd0e70791f5af297210c59 commit fb6782d4bdfaedc803fd0e70791f5af297210c59 Author: Matthew Thode <prometheanfire@gentoo.org> AuthorDate: 2020-02-28 16:29:16 +0000 Commit: Matthew Thode <prometheanfire@gentoo.org> CommitDate: 2020-02-28 16:29:46 +0000 dev-python/pysaml2: cleanup Bug: https://bugs.gentoo.org/710732 Package-Manager: Portage-2.3.84, Repoman-2.3.20 Signed-off-by: Matthew Thode <prometheanfire@gentoo.org> dev-python/pysaml2/Manifest | 1 - dev-python/pysaml2/pysaml2-4.6.3-r1.ebuild | 40 ------------------------------ dev-python/pysaml2/pysaml2-4.6.3.ebuild | 29 ---------------------- dev-python/pysaml2/pysaml2-4.6.5.ebuild | 40 ------------------------------ 4 files changed, 110 deletions(-) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e7a247aadc5e35bf5aed61f78f7e8b0d9ed21dfb commit e7a247aadc5e35bf5aed61f78f7e8b0d9ed21dfb Author: Matthew Thode <prometheanfire@gentoo.org> AuthorDate: 2020-02-28 16:28:00 +0000 Commit: Matthew Thode <prometheanfire@gentoo.org> CommitDate: 2020-02-28 16:29:44 +0000 dev-python/pysaml2: 4.6.5-r1 added fast stable for CVE-2020-5390 Bug: https://bugs.gentoo.org/710732 Package-Manager: Portage-2.3.84, Repoman-2.3.20 RepoMan-Options: --force Signed-off-by: Matthew Thode <prometheanfire@gentoo.org> dev-python/pysaml2/files/cve-2020-5390.patch | 189 +++++++++++++++++++++++++++ dev-python/pysaml2/metadata.xml | 2 +- dev-python/pysaml2/pysaml2-4.6.5-r1.ebuild | 42 ++++++ 3 files changed, 232 insertions(+), 1 deletion(-) fixed, fast stable with cleanup Thanks all, tree is clean. |