it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Moritz Muehlenhoff <jmm AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 5897-1] lemonldap-ng security update
- Date: Tue, 8 Apr 2025 16:57:16 +0000
- Authentication-results: lists.piratenpartei.de; dkim=none; spf=none (lists.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
- List-archive: https://lists.debian.org/msgid-search/Z/VVbCSgRq1UuFU5 AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=Xogq37J+ISu+h3XGuZiXkTP+AXfRyBTIJ+UAchd+tVk=; b=JN uMiHmJPG+UZyx8wvTU/gNqrpo0oQRRULM/PspD6K90A23G8+MMaoLrq2DTT51jyOoZXA+lyAA+p2w wFfPa4Rwh5k6zpXZVk3vOFJ0QtDnbhVxy05raRayM66XbJvSa8YM9hQfUd/u5yq5piOu0/l3NzO2M 498g87OnXRJqf9JBfJ+EpA4iaRcbdlfSjPt6gVLZwKZMLXFUoKObVVDUBVxadkMHMV1mHU7MJg/YJ oGe7x8w6RJUiz7LCQw+AiSVzU1GXpmf7Dm93EDBBujZdbKbT7KXGbQg0qqQmb8/MWzwyb3jo1s23I jgKzVjmFvpwg5Qb/VoV8GTrCgq1Acwow==;
- Old-return-path: <jmm AT seger.debian.org>
- Priority: urgent
- Resent-date: Tue, 8 Apr 2025 16:57:36 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <ZGFXdQsR7YI.A.zX7P.AWV9nB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-5897-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
April 08, 2025 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : lemonldap-ng
CVE ID : CVE-2025-31510
A cross-site scripting vulnerability has been discovered in
Lemonldap::NG, a Web-SSO system compatible with OpenID-Connect, CAS and
SAML, when using the "Choice" module: It permits to introduce HTML code
into the login page and if the default Content-Security-Policy headers
have been modified, it may be possible to inject JavaScript code.
For the stable distribution (bookworm), this problem has been fixed in
version 2.16.1+ds-deb12u6.
We recommend that you upgrade your lemonldap-ng packages.
For the detailed security status of lemonldap-ng please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/lemonldap-ng
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmf1VScACgkQEMKTtsN8
TjYPjw/9HrwQzMz9+QbK+V56JSlfoOT3Ccg5tVPlmKkHKd4wsC8nDmQ2F2gPbXaK
zyI0ZKW8sggMt81P30aBGs7AY6lhkXb5tSbQK/4i1EimGDOh1+mCUt99AmJRkrR/
J9Gik4eHFtJAB7oI2fGkDCS7cU+QfhuOGnK4J/YK6b3TJkr0teLxP1U6aWfzG0vF
C0sezXHIfJopY6QFOzHAgE7koVCK4WV5Jsa4VZ3SjBk9pFFNuHGeRfjUyOHiNYbs
IPvT/YdjfEEWUrTbla9bsWu2UQ6fQVM+Iua+72FOrYSwqvW++RQjADlBU9QVekRy
eFCXK22p9ICbp6mnNydnjL6gHsrmQo1PKFd771gfwm34zspHkTytgHdV1m++xmhh
1WAperBFOi86/CKedJL8mgzUm8/MevQ4JRSN03go/WLsVg6BXXO1R7TeTB2LYK/x
AHcQteiFqrMoDzxIfyEJ54zxYj9FX3QpK2N2jJgVQBkDriAoWHjFkko11mNqJyjv
azqgxw6dyVQRtKG4NaGsA7my9W81PFY+4Qsg4Ma0xqnuDq4vATSnidyM44aHCedU
yJOQO8Uj8cQ3siOhPwI+vnp+olI0oA4Qbc0tx4/FbdzAiv0kyMjCdUdD3bSmnokf
UBpGzX1LDlI7OJIRPc8RN9LDv/uhQoaFtF0IN5U/c7Htlh23p/Q=
=hJfd
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 5897-1] lemonldap-ng security update, Moritz Muehlenhoff, 08.04.2025
Archiv bereitgestellt durch MHonArc 2.6.19+.