-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 24 Nov 2023 08:15:30 -0500 Source: glewlwyd Binary: glewlwyd glewlwyd-dbgsym Architecture: s390x Version: 2.5.2-2+deb11u3 Distribution: bullseye Urgency: medium Maintainer: s390x Build Daemon (zandonai) Changed-By: Nicolas Mora Description: glewlwyd - Single-Sign-On server with multiple factor authentication Changes: glewlwyd (2.5.2-2+deb11u3) bullseye; urgency=medium . * d/patches: Fix CVE-2022-27240 possible buffer overflow during webauthn signature assertion * d/patches: Fix CVE-2022-29967 static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal * d/glewlwyd-common.install: copy bootstrap, jquery, fork-awesome instead of linking it * d/patches: Fix CVE-2023-49208: possible buffer overflow during FIDO2 signature validation in webauthn registration Checksums-Sha1: bea4ebb27dfdeef640891e803ed46cba3ad2bcbc 1063792 glewlwyd-dbgsym_2.5.2-2+deb11u3_s390x.deb 8aeb1981adbfc4b12292c4bf4469a7b116ff9402 8692 glewlwyd_2.5.2-2+deb11u3_s390x-buildd.buildinfo a48afc3804ee15404a5543e1a36ed1722172f82d 428668 glewlwyd_2.5.2-2+deb11u3_s390x.deb Checksums-Sha256: 58191ef0a049d503d059541ec7ae1340b48c0f1115cb427db912cc5d0b50231f 1063792 glewlwyd-dbgsym_2.5.2-2+deb11u3_s390x.deb 4681477fca2b749f045f48d27f7663cf69acc59f4f65b8c334706ec43c973671 8692 glewlwyd_2.5.2-2+deb11u3_s390x-buildd.buildinfo ef12ff057c5a7cc396adb6f01c37d952a813b7131452615dd9f76616839d4146 428668 glewlwyd_2.5.2-2+deb11u3_s390x.deb Files: a9600a191f2431b0ee7e7d1b1e87a363 1063792 debug optional glewlwyd-dbgsym_2.5.2-2+deb11u3_s390x.deb e56e81954e7cabfbd75bf577f287826c 8692 web optional glewlwyd_2.5.2-2+deb11u3_s390x-buildd.buildinfo aacd1dc15d1371b694a8f54e07c7ea7f 428668 web optional glewlwyd_2.5.2-2+deb11u3_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEctqRAwcjFMIrbct74euoNlQ3ywQFAmaW91QACgkQ4euoNlQ3 ywR9QRAAncrq+YgB0FgqKzIs78GB2Px8AqLmA4ybX43mXW3LULO/pcVS1uO4Fl7w 148z0dSG91C/6aGrs9E5y+ef3uYHdThKcQg2k2yytyYw90XYq1Qp+KynkcjqltkU 4nKDOlF6wcQ+rdst1p6zj7nSppkabA69tlicST/Z4Iq8elXcOYF1FtBWkjSZl7bp Dt/9xU4x079QLkJ5Zg08UvqXK6tYHZib6+Fe0oxQrtsmRXDDeffP/KjBhdkbfyVK xJbmSDErCZ6TlOKR0tK907HGHQmDN9VBDmX8VwRLVEmszXrjV4Pr+w3X2osDcnQS NJNCu/dOX83uoEzP/1eHcW97HlqyLkanHLdhtv1nG5BLyVmnVE0Lbr671FNgmvAl u22DUGbYg+NFqrIQBCpsmqtfb8bHENW3z6oWZrLOlhK59LBVteBkrOIzGO6JE+wR q3xWG3EN6Ds1H7flufvQaBGW7K2EwF3lp5G3xrTLtwKeWJI+OGnYzW4bddRkJHHg Gt1cmbhAMcExPPENPYz+zeBAw6T8ud+ddNwKyDNZX8R1f730mc0NJoDkgzANm4h5 gn8KDEQBXc5h9UPF33L+nbOsCE0k/JV37i6IQwIQmKJ8O62c7gqURS7S1iKcGgRn FRgEXmx1bZf+QVJWBeaK8leqlOilmyJY6OYQ/FMLu4KHzRhgX98= =lX2Q -----END PGP SIGNATURE-----