Debian release 4.5.3-1 Format: 1.8 Date: Wed, 15 May 2013 13:57:37 -0700 Source: webauth Binary: libapache2-mod-webauth libapache2-mod-webkdc libapache2-webauth libapache2-webkdc libwebauth-perl libwebauth10 libwebauth-dev libwebkdc-perl webauth-tests webauth-utils webauth-weblogin Architecture: source i386 all Version: 4.5.3-1 Distribution: experimental Urgency: low Maintainer: Russ Allbery <rra@debian.org> Changed-By: Russ Allbery <rra@debian.org> Description: libapache2-mod-webauth - Apache modules for WebAuth authentication libapache2-mod-webkdc - Apache modules for a WebAuth authentication KDC libapache2-webauth - Transitional package for WebAuth Apache modules libapache2-webkdc - Transitional package for WebAuth authentication KDC libwebauth-dev - Development files for WebAuth authentication libwebauth-perl - Perl library for WebAuth authentication libwebauth10 - Shared libraries for WebAuth authentication libwebkdc-perl - Perl libraries for WebAuth central login server webauth-tests - Tests for the WebAuth authentication modules webauth-utils - Command-line utilities for WebAuth authentication webauth-weblogin - Central login server for WebAuth authentication Changes: webauth (4.5.3-1) experimental; urgency=low . * New upstream release. - SECURITY: Clear header state between requests to avoid information leaks or infinite redirects for WebLogin servers using FastCGI and $REMUSER_REDIRECT (not the default). The vulnerability was introduced in WebAuth 4.4.1. All versions of WebAuth with this vulnerability were only uploaded to Debian experimental. Checksums-Sha1: 2fe7792cd458abcad0cf932ebc7b8c09f03ec4e5 2211 webauth_4.5.3-1.dsc 8b086b9204ed998462511af7cb17d4f809a1947b 861932 webauth_4.5.3.orig.tar.xz fbb4fee1f143bcdaff015e062c91e287b519eb35 26136 webauth_4.5.3-1.debian.tar.xz 2e1792cafe0266df00db943a9b0ba3edb0242437 242348 libapache2-mod-webauth_4.5.3-1_i386.deb 8201219b079af11258d288d6b610eb0c40fc1a2b 107268 libapache2-mod-webkdc_4.5.3-1_i386.deb a09c45ad852fb9eb39fac7bd76e490c33d3498a4 49192 libapache2-webauth_4.5.3-1_all.deb 99123bf7cf1edd77d4927c106a7e18c1919b5218 48544 libapache2-webkdc_4.5.3-1_all.deb b67554ba8e086e3bc2547700b0f8fe7af8b6369b 142810 libwebauth-perl_4.5.3-1_i386.deb 62cf94f4d299e6a1d7e05a868d937516d1e5cbd3 82738 libwebauth10_4.5.3-1_i386.deb e4bd9ce69e6b2b83d47ac27eb8ba779b71fc9e13 98138 libwebauth-dev_4.5.3-1_i386.deb ac7dfe49f3e6a4263ec800c55fdbfaa6cee92bcc 116272 libwebkdc-perl_4.5.3-1_all.deb bce2b8f1c489d96924a26f57605fb128f81c39ca 59396 webauth-tests_4.5.3-1_all.deb 095d5952a2cc49857fb3b94fed30a4e13693e49c 57646 webauth-utils_4.5.3-1_i386.deb 12ce3f16ca8f44dc4f11b5895fced0de50046c11 117280 webauth-weblogin_4.5.3-1_all.deb Checksums-Sha256: 57a07f89c9af4ef8d3e7bcf9e4a9caa5ae089ae50b301ce26bc5e50ceb581aac 2211 webauth_4.5.3-1.dsc 2b19b756da31aa1835ef59c4ad3667b1ca8e917917cb3f14252de4cb41265d6a 861932 webauth_4.5.3.orig.tar.xz d2da637f1342fc6b3c3380f941e58baa797de7f30150eb2362140588b9a945b0 26136 webauth_4.5.3-1.debian.tar.xz 0b9f2e2a25117e23337720544632eb66bee2942123a7f5f870de819a41abcdea 242348 libapache2-mod-webauth_4.5.3-1_i386.deb 4be8a45b312082180fc1a83f40dc4427e928858c6114a800bc23dfada1b19858 107268 libapache2-mod-webkdc_4.5.3-1_i386.deb c73667879a69a8dbe4aeacacda0988cbee3cedf3f35af6113f0d942d702a2353 49192 libapache2-webauth_4.5.3-1_all.deb 92d283495c8997c8397f90158aefb9e8cd68786185f094cce18822acf4552a77 48544 libapache2-webkdc_4.5.3-1_all.deb 1d391ec610e1a1d9bb768eb0c2927065929a7677f07e26f0ce02c07997ec3de3 142810 libwebauth-perl_4.5.3-1_i386.deb 003b03eede7ad2ce29ca09afcdf9de047a1693221a3a13608ea2cf267dc6bbde 82738 libwebauth10_4.5.3-1_i386.deb bfadd213762400f00035b2af9dc9ad4da22ff3e355df3be6bf0b80858c8877c0 98138 libwebauth-dev_4.5.3-1_i386.deb bba75e434dea7bd933c511ccc13e1c325ecf33f0c2e55b754f6dba0596adce6c 116272 libwebkdc-perl_4.5.3-1_all.deb e012f0e9e21207f443c30a65018d30ec67ae550d93a23974a3e41a92e4cb7e84 59396 webauth-tests_4.5.3-1_all.deb c0cd4b365d13a9f2a16855ca3cf900d888540e4d5818d885df8eecc11c2ae115 57646 webauth-utils_4.5.3-1_i386.deb 149fcd9c74d2b14b93a9b4eb06b5cca1aa0e5c7ba113e96f6ac75b48c134e309 117280 webauth-weblogin_4.5.3-1_all.deb Files: f6e34d60423651e37d9c156183bb6ea0 2211 web optional webauth_4.5.3-1.dsc 3aabcb99a80c30870f77b87a1a31e437 861932 web optional webauth_4.5.3.orig.tar.xz 37a2c5266e2b0ab03af86687b90b04b7 26136 web optional webauth_4.5.3-1.debian.tar.xz e6e47a987b6eec49986408ed12246c7d 242348 httpd optional libapache2-mod-webauth_4.5.3-1_i386.deb 785ae0c04d6d087925f9667d5977e42e 107268 httpd optional libapache2-mod-webkdc_4.5.3-1_i386.deb ecf11b275213677a467cae675fa9d901 49192 oldlibs extra libapache2-webauth_4.5.3-1_all.deb 154e01128a80838f44dceabe17d763e7 48544 oldlibs extra libapache2-webkdc_4.5.3-1_all.deb 62666970bdd3ccba33be2e06a43dbca2 142810 perl optional libwebauth-perl_4.5.3-1_i386.deb db1fdd8117385fe255e0b88ef2e8bc86 82738 libs optional libwebauth10_4.5.3-1_i386.deb 910a7679e8b3be1ce901b475d1122a0c 98138 libdevel extra libwebauth-dev_4.5.3-1_i386.deb 83f7b4208dff174a38d98bd5da3db0eb 116272 perl optional libwebkdc-perl_4.5.3-1_all.deb 2adb122939479f933a047007af4ad3bb 59396 web optional webauth-tests_4.5.3-1_all.deb c509758ca6a4d0abf7e0cf2249d8df0e 57646 web optional webauth-utils_4.5.3-1_i386.deb ff4e162f7d883cade867e695769f7f0f 117280 web optional webauth-weblogin_4.5.3-1_all.deb