xmltooling Debian release 1.6.4-1 Format: 1.8 Date: Wed, 28 Feb 2018 10:39:05 +0100 Source: xmltooling Binary: libxmltooling7 libxmltooling-dev xmltooling-schemas libxmltooling-doc Architecture: source Version: 1.6.4-1 Distribution: unstable Urgency: high Maintainer: Debian Shib Team <pkg-shibboleth-devel@lists.alioth.debian.org> Changed-By: Ferenc Wágner <wferi@debian.org> Description: libxmltooling-dev - C++ XML parsing library with encryption support (development) libxmltooling-doc - C++ XML parsing library with encryption support (API docs) libxmltooling7 - C++ XML parsing library with encryption support (runtime) xmltooling-schemas - XML schemas for XMLTooling Changes: xmltooling (1.6.4-1) unstable; urgency=high . * [6c27b19] New upstream security release 1.6.4 DSA-4126-1, CVE-2018-0489: additional data forgery flaws These flaws allow for changes to an XML document that do not break a digital signature but alter the user data passed through to applications enabling impersonation attacks and exposure of protected information. https://shibboleth.net/community/advisories/secadv_20180227.txt https://issues.shibboleth.net/jira/browse/CPPXT-128 * [621ab19] Refresh our patches Checksums-Sha1: 3b4aca53462d969db11fec6d719f5e299df9c7c1 1579 xmltooling_1.6.4-1.dsc dea065379b611bbc0f1e9320fcb36662c7884d8a 581796 xmltooling_1.6.4.orig.tar.bz2 caa17312e4529c4a991bc447d899017b95ae3a51 71596 xmltooling_1.6.4-1.debian.tar.xz d31ee917c13ef5c2f1fbae73bdc75357134c0761 8706 xmltooling_1.6.4-1_amd64.buildinfo Checksums-Sha256: 0eee0e2f421eca3a368baed868a9273054bb114f13e99ab2766e317542bae512 1579 xmltooling_1.6.4-1.dsc 4c0c4a08b8c55f1210673281f37fc95b6d1d365a8cdc726fd189dea96c45efca 581796 xmltooling_1.6.4.orig.tar.bz2 d9c12fa2723995d083382fe4798b801e4d3b05b90a9026140a375a39d06a5bae 71596 xmltooling_1.6.4-1.debian.tar.xz bd92f789fd3e76a25a8b861357bb7b5a61b353295a65be2864dd66674cf81065 8706 xmltooling_1.6.4-1_amd64.buildinfo Files: 5aa6f076861a0316af5bcf37ea0100db 1579 libs optional xmltooling_1.6.4-1.dsc 27dca3e406526430c465ce2582ea9ea1 581796 libs optional xmltooling_1.6.4.orig.tar.bz2 067ac8cd65422f0c05b2ff9981b8f2f8 71596 libs optional xmltooling_1.6.4-1.debian.tar.xz 19773a7f78a384693428f345b1e2aec0 8706 libs optional xmltooling_1.6.4-1_amd64.buildinfo