Debian Security Advisory

DLA-290-2 opensaml2 -- LTS security update

Date Reported:
10 Aug 2015
Affected Packages:
opensaml2
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2015-0851.
More information:

It was discovered that opensaml2, a Security Assertion Markup Language library, needed to be rebuilt against a fixed version of the xmltooling package due to its use of macros vulnerable to CVE-2015-0851 as fixed in the DSA 3321-1 update.

For Debian 6 Squeeze, these issues have been fixed in opensaml2 version 2.3-2+squeeze2