Bug 43783 - Upgrade simplesamlphp version
Upgrade simplesamlphp version
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: SAML
UCS 4.2
Other Linux
: P5 normal (vote)
: UCS 4.2
Assigned To: Florian Best
Erik Damrose
: interim-3
: 43873 (view as bug list)
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-03-10 11:52 CET by Florian Best
Modified: 2017-04-04 18:29 CEST (History)
4 users (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Florian Best univentionstaff 2017-03-10 11:52:07 CET
There are 3 security vulnerabilities in simplesamlphp, fixed in debian stretch but not in wheezy/jessy:

https://simplesamlphp.org/security/201612-01
https://simplesamlphp.org/security/201612-02
https://simplesamlphp.org/security/201612-03

We should upgrade our simplesamlphp package in UCS 4.2.
Backport to 4.1 as well?
Comment 1 Florian Best univentionstaff 2017-03-10 12:05:21 CET
The version from stretch has been imported:
"""
Target Release: RelTag(major=4, minor=2, subminor=0, updatelevel=0, product='ucs', id=78)
Merging possible patches from preversions
A    /tmp/tmpnjY4ZH/1.13.2-1
Checked out revision 17388.
Merging patch from 1.13.2-1
A         1.14.11-1
Adding         1.14.11-1

Committed revision 17389.
Writing new source revision to database
Pruning older revisions in this release tag:
1.13.2-1
Merged id 83434 into release 4.2-0-0
Imported from deb suite=stretch
Old Source Revision has been replaced: 75033
New Source Revision: 83434
"""
The memcache patch has been removed as it is part of upstream:
r17390 | Bug #43783: remove patch

The Nutzername → Benutzername patch has been rebased:
r17391 | Bug #43783: adjust patch

Package: simplesamlphp
Version: 1.14.11-1A~4.2.0.201703101201
Comment 2 Florian Best univentionstaff 2017-03-10 12:31:08 CET
Changed also the dependency from "php" to "php5" and restored dependency from previous version:
r17392 | Bug #43783: fix PHP dependencies
Comment 3 Erik Damrose univentionstaff 2017-03-14 17:43:05 CET
OK: simplesamlphp update
reopen: changelog entry missing
Comment 4 Florian Best univentionstaff 2017-03-14 18:09:57 CET
r77703 | Bug #43783: Changelog
Comment 5 Erik Damrose univentionstaff 2017-03-14 18:14:04 CET
Thanks, verified
Comment 6 Florian Best univentionstaff 2017-03-15 15:58:52 CET
*** Bug 43873 has been marked as a duplicate of this bug. ***
Comment 7 Stefan Gohmann univentionstaff 2017-04-04 18:29:38 CEST
UCS 4.2 has been released:
 https://docs.software-univention.de/release-notes-4.2-0-en.html
 https://docs.software-univention.de/release-notes-4.2-0-de.html

If this error occurs again, please use "Clone This Bug".