FFe: Sync libapache2-mod-auth-openidc 1.5.5-1 (universe) from Debian testing (main)

Bug #1376308 reported by Hans Zandbelt
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
libapache2-mod-auth-openidc (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Please sync libapache2-mod-auth-openidc 1.5.5-1 (universe) from Debian testing (main)

Explanation of FeatureFreeze exception:
- fix builds/runs on big endian machines
- improved security:
  - using HttpOnly on cookies
  - prevent timing attacks
  - check for open redirects
- fix cache initialization/destroy leak

For more detail see: https://github.com/pingidentity/mod_auth_openidc/releases

Changelog entries since current utopic version 1.5.3-1:

libapache2-mod-auth-openidc (1.5.5-1) unstable; urgency=medium

  * use HttpOnly on cookies; set OIDCCookiePath to /

 -- Hans Zandbelt <email address hidden> Tue, 26 Aug 2014 09:23:43 +0200

libapache2-mod-auth-openidc (1.5.4-3) unstable; urgency=medium

  * changelog line was too long; correct/simplify watch file

 -- Hans Zandbelt <email address hidden> Thu, 14 Aug 2014 15:51:02 +0200

libapache2-mod-auth-openidc (1.5.4-2) unstable; urgency=medium

  * correct debian directory for wheezy/jessie; watch file check .orig.tar.gz

 -- Hans Zandbelt <email address hidden> Thu, 14 Aug 2014 15:03:52 +0200

libapache2-mod-auth-openidc (1.5.4-1) unstable; urgency=medium

  * fix big endian issue

 -- Hans Zandbelt <email address hidden> Thu, 14 Aug 2014 12:59:11 +0200

libapache2-mod-auth-openidc (1.5.3-2) unstable; urgency=medium

  * build/test on big endian arch

 -- Hans Zandbelt <email address hidden> Sun, 3 Aug 2014 22:27:07 +0200

Revision history for this message
Hans Zandbelt (hzandbelt) wrote :

while we're at it: 1.6.0-1 that goes in to Debian testing now fixes an additional build dependency issue and some more security improvements

Revision history for this message
Scott Kitterman (kitterman) wrote :

$ rmadison libapache2-mod-auth-openidc
 libapache2-mod-auth-openidc | 1.5.1-1 | utopic/universe | source, amd64, arm64, armhf, i386, powerpc, ppc64el
 libapache2-mod-auth-openidc | 1.6.0-1 | vivid/universe | source, amd64, arm64, armhf, i386, powerpc, ppc64el

Changed in libapache2-mod-auth-openidc (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.