Debian Security Advisory
DLA-290-2 opensaml2 -- LTS security update
- Date Reported:
- 10 Aug 2015
- Affected Packages:
- opensaml2
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2015-0851.
- More information:
-
It was discovered that opensaml2, a Security Assertion Markup Language library, needed to be rebuilt against a fixed version of the xmltooling package due to its use of macros vulnerable to CVE-2015-0851 as fixed in the DSA 3321-1 update.
For Debian 6
Squeeze
, these issues have been fixed in opensaml2 version 2.3-2+squeeze2