[cpp-sp] 04/42: Mention CVE for the world-readable key issue

Scott Cantor cantor.2 at osu.edu
Thu Dec 20 19:44:21 EST 2018


This is an automated email from the git hooks/post-receive script.

scantor pushed a commit to annotated tag debian/2.4.2+dfsg-1
in repository cpp-sp.

View the commit online:
http://git.shibboleth.net/view/?p=cpp-sp.git;a=commit;h=fc2fcc33b5dd05eca1b3dad1c887a819e5e3c26e

commit fc2fcc33b5dd05eca1b3dad1c887a819e5e3c26e
Author: Russ Allbery <rra at debian.org>
AuthorDate: Wed Nov 24 13:29:22 2010 -0800

    Mention CVE for the world-readable key issue
    
    Add CVE for the world-readable certificate key to the changelog entry
    of 2.3.1+dfsg-2 so that the security tracker knows it was fixed.
---
 debian/changelog | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/debian/changelog b/debian/changelog
index 7b6962f..0e495ea 100644
--- a/debian/changelog
+++ b/debian/changelog
@@ -12,7 +12,7 @@ shibboleth-sp2 (2.3.1+dfsg-3) UNRELEASED; urgency=low
 shibboleth-sp2 (2.3.1+dfsg-2) unstable; urgency=low
 
   * Modify shib-keygen to create the new certificate key group-readable by
-    _shibd and not world-readable.  (Closes: #571631)
+    _shibd and not world-readable.  (Closes: #571631, CVE-2010-2450)
   * Force source format 1.0 for now since it makes backporting easier.
   * Update debhelper compatibility level to V7.
     - Use dh_prep instead of dh_clean -k.

-- 
To stop receiving notification emails like this one, please contact
the administrator of this repository.


More information about the commits mailing list