Bug#793855: DoS, Shibboleth SP software crashes on well-formed but invalid XML (CVE-2015-0851)

Ferenc Wagner wferi at niif.hu
Wed Nov 4 11:14:39 UTC 2015


Salvatore Bonaccorso <carnil at debian.org> writes:

> On Thu, Sep 24, 2015 at 08:54:08AM +0200, Ferenc Wagner wrote:
>
>> Salvatore Bonaccorso <carnil at debian.org> writes:
>> 
>>> Any news for the fix to unstable for CVE-2015-0851?
>> 
>> Sorry, I got bogged down in another department.  It isn't forgotten,
>> though, I expect to tend to it in a couple of days.
>
> *ping*? ;-)

I clearly failed to live up to my promise.  Sorry for that.  Things are
shaping up, though, I really expect to start packaging the newest stack
next week latest.  (That will take care of the C++ transition, too.)
-- 
Regards,
Feri.



More information about the Pkg-shibboleth-devel mailing list