-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 24 Nov 2023 08:15:30 -0500 Source: glewlwyd Binary: glewlwyd glewlwyd-dbgsym Architecture: i386 Version: 2.5.2-2+deb11u3 Distribution: bullseye Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Nicolas Mora Description: glewlwyd - Single-Sign-On server with multiple factor authentication Changes: glewlwyd (2.5.2-2+deb11u3) bullseye; urgency=medium . * d/patches: Fix CVE-2022-27240 possible buffer overflow during webauthn signature assertion * d/patches: Fix CVE-2022-29967 static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal * d/glewlwyd-common.install: copy bootstrap, jquery, fork-awesome instead of linking it * d/patches: Fix CVE-2023-49208: possible buffer overflow during FIDO2 signature validation in webauthn registration Checksums-Sha1: 0290fd780c6938f5179b03f8f559b3115cba3d14 770044 glewlwyd-dbgsym_2.5.2-2+deb11u3_i386.deb 2be969d767d13fb97ba324aedf145bb406ae7148 8708 glewlwyd_2.5.2-2+deb11u3_i386-buildd.buildinfo 6744f69732073930de1af14e945569fbfcdcfad2 510980 glewlwyd_2.5.2-2+deb11u3_i386.deb Checksums-Sha256: ea9aeadca9bc672b6c199a899fd47a1d46306b7bed874acf8219d7d5208e1a03 770044 glewlwyd-dbgsym_2.5.2-2+deb11u3_i386.deb 73b28f86f70c2ba6b8d62e99c7b0ce2cdb1c85ab6c460eb33c09598a172c0f50 8708 glewlwyd_2.5.2-2+deb11u3_i386-buildd.buildinfo bab313f1d1313d2b93a1cbefefb7de944c1227fe4b4ec0e2bf2c57441298915b 510980 glewlwyd_2.5.2-2+deb11u3_i386.deb Files: a82c2a357f8ecff710a0489243c23f28 770044 debug optional glewlwyd-dbgsym_2.5.2-2+deb11u3_i386.deb 3501b5dc85dccc273da259e0b369bf70 8708 web optional glewlwyd_2.5.2-2+deb11u3_i386-buildd.buildinfo bd689c42df6ca3aabd1d322d95739618 510980 web optional glewlwyd_2.5.2-2+deb11u3_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEErEDrIdpJkzFMm6K+PyQET5WCY90FAmaXC2sACgkQPyQET5WC Y93M9g/+Igr1BJuIUZaeaDosCvf8vnoz5MYWmQmlbuxsypd3Tun4awg8rSPxRoOb +UVCJqTmfyIGiomnCNyklonjjBLuzh44Cd0QHJMk1Mafy+2IYejBDH16u8pj6Qs1 jZMRUtSdCOOsTwy4tWd9Mnf9vDaL8vMCBCGJIfT8VbJz4XX3d6NkIaTf0gy0E0eA xI89VRjePKp0LZ6g2bCUhbmEyYqIyCs+tAWZEQbCFL4dmWWHLUSw5uxeofYPA63r pnV6Mut8kRjFGFtuB8EzgApys04pYsy77MrdqQlY56k33I1fG/ya1C1luV/YdN66 l2xNnu2GZoRwzK1BzbJowmywk7UlkAHKYB1EaOgpEmxJtXHiwzw++B4KzynJ85Lq EKxu0W08FOYHNHvxaGbFql4A3ILgrBZGYadno8RWBcZ13odSJzDYTIE15s6IOVFb TVNkE/jXWl1emBGEP7koJ/pz1cvF6mbNsBtZJQiLMfiNLL9AEEnaDtkqlikt5cDm CmclSz0HDEo1qFa+KIu0nFEcXo0zdrezjTuNl5iYj93l+RglRSBEukiFhycMN5zd HorfAlInYyRY3Jv0uTR4FcITRVd/mDLX5OxK3ndUXZapRI1PuLRuUmxgUPz0QVmZ syntYxY+ayT0b9J7RRIlE140rvhZ+iJJZ6mB+ja2S9ukWjh517s= =4llu -----END PGP SIGNATURE-----