- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Moritz Schlarb
- Date:
- 2022-07-09 10:51:27 UTC
- Severity:
- normal
- Tags:
Dear stable release managers and security team,
I kindly ask you to allow version 2.4.9.4 of the aforementioned
package to be included in proposed-updates to fix CVE-2021-39191
and the regression mentioned in #891224#49ff.
I would prefer to just be able to introduce this plainly as the
(smaller-than-patch) upstream release for simplicity.
[ Reason ]
To quote the corresponding changelog entry:
libapache2-mod-auth-openidc (2.4.9.4-1) unstable; urgency=medium
* New upstream version 2.4.9.4
* Fix "CVE-2021-39191" (Closes: #993648)
* 2.4.9.2 fixed a regression regarding segfault at reload/restart
(Closes: #883616, #891224, #868949)
Control: tags -1 + confirmed +libapache2-mod-auth-openidc (2.4.9.4-1+deb11u1) bullseye; urgency=medium + + * New upstream version 2.4.9.4 If you're importing a new upstream version, it's slightly more conventional to use 2.4.9.4-0+deb11u1, as you haven't based the upload on a previous 2.4.9.4-1. I wouldn't object hugely to the form you've used though. Please go ahead. Regards, Adam
package release.debian.org tags 1006316 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: libapache2-mod-auth-openidc Version: 2.4.9.4-0+deb11u1 Explanation: new upstream stable release; fix open redirect issue [CVE-2021-39191]; fix crash on reload / restart
package release.debian.org tags 1006316 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: libapache2-mod-auth-openidc Version: 2.4.9.4-0+deb11u1 Explanation: new upstream stable release; fix open redirect issue [CVE-2021-39191]; fix crash on reload / restart
(re-sending with fixed bug numbers) Hi, The updates discussed in these bugs were included in today's bullseye point release. Regards, Adam