shibboleth-sp 3.0.4+dfsg1-1ubuntu0.2 source package in Ubuntu

Changelog

shibboleth-sp (3.0.4+dfsg1-1ubuntu0.2) focal-security; urgency=high

  * SECURITY UPDATE: Session recovery feature contains a null pointer
    deference (LP: #1926250)
    - debian/patches/SSPCPP-927-Check-for-missing-DataSealer-during-cookie-
      rec.patch: Check for missing DataSealer during cookie recovery
    - https://shibboleth.net/community/advisories/secadv_20210426.txt
    - https://issues.shibboleth.net/jira/browse/SSPCPP-927
    - CVE-2021-31826

 -- Etienne Dysli Metref <email address hidden>  Thu, 10 Jun 2021 11:30:02 +0200

Upload details

Uploaded by:
Etienne Dysli Metref
Sponsored by:
Steve Beattie
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
web
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section
Focal updates universe misc
Focal security universe misc

Downloads

File Size SHA-256 Checksum
shibboleth-sp_3.0.4+dfsg1.orig.tar.xz 614.9 KiB b327701d111da4b5da370eddc945c382abc378ff9445e1eda9554c0d7e6f1dca
shibboleth-sp_3.0.4+dfsg1-1ubuntu0.2.debian.tar.xz 77.7 KiB 49f99596451f4fce84231f305b1464f2d004670aa5691b02ca694169d2f963c4
shibboleth-sp_3.0.4+dfsg1-1ubuntu0.2.dsc 3.0 KiB cf291455490db6c8f8ba00b84f7ab9691246d2b4146d1f39df65233307129793

View changes file

Binary packages built by this source

libapache2-mod-shib: Federated web single sign-on system (Apache module)

 The Shibboleth System is a standards based software
 package for web single sign-on across or within organizational boundaries.
 It supports authorization and attribute exchange using the OASIS SAML 2.0
 protocol. Shibboleth allows sites to make informed authorization decisions
 for individual access of protected online resources while allowing users to
 establish their identities with their local authentication systems.
 .
 This package contains the Shibboleth Apache module for service providers
 (web servers providing resources protected by Shibboleth) and the
 supporting shibd daemon.

libapache2-mod-shib-dbgsym: debug symbols for libapache2-mod-shib
libapache2-mod-shib2: transitional package

 This is a transitional package. It can safely be removed.

libshibsp-dev: Federated web single sign-on system (development)

 The Shibboleth System is a standards based software
 package for web single sign-on across or within organizational boundaries.
 It supports authorization and attribute exchange using the OASIS SAML 2.0
 protocol. Shibboleth allows sites to make informed authorization decisions
 for individual access of protected online resources while allowing users to
 establish their identities with their local authentication systems.
 .
 This package contains the headers and other necessary files to build
 applications that use the Shibboleth SP library.

libshibsp-doc: Federated web single sign-on system (API docs)

 The Shibboleth System is a standards based software
 package for web single sign-on across or within organizational boundaries.
 It supports authorization and attribute exchange using the OASIS SAML 2.0
 protocol. Shibboleth allows sites to make informed authorization decisions
 for individual access of protected online resources while allowing users to
 establish their identities with their local authentication systems.
 .
 This package contains the Shibboleth SP library API documentation.

libshibsp-plugins: Federated web single sign-on system (plugins)

 The Shibboleth System is a standards based software
 package for web single sign-on across or within organizational boundaries.
 It supports authorization and attribute exchange using the OASIS SAML 2.0
 protocol. Shibboleth allows sites to make informed authorization decisions
 for individual access of protected online resources while allowing users to
 establish their identities with their local authentication systems.
 .
 This package contains plugins for the Shibboleth SP library.

libshibsp-plugins-dbgsym: debug symbols for libshibsp-plugins
libshibsp8: Federated web single sign-on system (runtime)

 The Shibboleth System is a standards based software
 package for web single sign-on across or within organizational boundaries.
 It supports authorization and attribute exchange using the OASIS SAML 2.0
 protocol. Shibboleth allows sites to make informed authorization decisions
 for individual access of protected online resources while allowing users to
 establish their identities with their local authentication systems.
 .
 This package contains the Shibboleth SP runtime library.

libshibsp8-dbgsym: debug symbols for libshibsp8
shibboleth-sp-common: Federated web single sign-on system (common files)

 The Shibboleth System is a standards based software
 package for web single sign-on across or within organizational boundaries.
 It supports authorization and attribute exchange using the OASIS SAML 2.0
 protocol. Shibboleth allows sites to make informed authorization decisions
 for individual access of protected online resources while allowing users to
 establish their identities with their local authentication systems.
 .
 This package contains common files used by the Shibboleth SP library,
 Apache module, and daemon, primarily configuration files and schemas.

shibboleth-sp-utils: Federated web single sign-on system (daemon and utilities)

 The Shibboleth System is a standards based software
 package for web single sign-on across or within organizational boundaries.
 It supports authorization and attribute exchange using the OASIS SAML 2.0
 protocol. Shibboleth allows sites to make informed authorization decisions
 for individual access of protected online resources while allowing users to
 establish their identities with their local authentication systems.
 .
 This package contains the daemon that handles attribute requests and
 maintains session information for the SP. It is used internally by the
 Apache module (libapache2-mod-shib2), but may be useful independently in
 some circumstances. It also contains some other useful Shibboleth SP
 utility programs and the FastCGI authorizer and responder.

shibboleth-sp-utils-dbgsym: debug symbols for shibboleth-sp-utils
shibboleth-sp2-common: transitional package

 This is a transitional package. It can safely be removed.

shibboleth-sp2-utils: transitional package

 This is a transitional package. It can safely be removed.