-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 16 Apr 2025 10:56:55 +0200 Source: libapache2-mod-auth-openidc Binary: libapache2-mod-auth-openidc libapache2-mod-auth-openidc-dbgsym Architecture: armel Version: 2.4.12.3-2+deb12u3 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-06) Changed-By: Moritz Schlarb Description: libapache2-mod-auth-openidc - OpenID Connect Relying Party implementation for Apache Closes: 1102413 Changes: libapache2-mod-auth-openidc (2.4.12.3-2+deb12u3) bookworm-security; urgency=high . * Fix CVE-2025-31492 "protected content leakage when using OIDCProviderAuthRequestMethod POST" Backported applicable portions from upstream fix in https://github.com/OpenIDC/mod_auth_openidc/commit/b59b8ad63411857090ba1088e23fe414c690c127 (Closes: #1102413) Checksums-Sha1: 55a9517567da379bfbc44bb7efd05aa37d9610ee 322756 libapache2-mod-auth-openidc-dbgsym_2.4.12.3-2+deb12u3_armel.deb 2802e6412c79589229ff5fcd29dc50860594f18f 7936 libapache2-mod-auth-openidc_2.4.12.3-2+deb12u3_armel-buildd.buildinfo 7f7b92287269da600ace4889c31dcf65429a55f0 176188 libapache2-mod-auth-openidc_2.4.12.3-2+deb12u3_armel.deb Checksums-Sha256: ab6106dc47bb133fc12f07d5b66db92c6e17bd3e9c34e7694693f6e48e315867 322756 libapache2-mod-auth-openidc-dbgsym_2.4.12.3-2+deb12u3_armel.deb 922c21291a818da1d3a5dae3bd18659455a1d6d22efb25535ab4e069b4259ae9 7936 libapache2-mod-auth-openidc_2.4.12.3-2+deb12u3_armel-buildd.buildinfo 3e6f9052ff2832507127a0a859faaeb66ea50df4eef44136471c0184ce6d10e6 176188 libapache2-mod-auth-openidc_2.4.12.3-2+deb12u3_armel.deb Files: 16a8d22ea41e9597ac1ba795957e8f7b 322756 debug optional libapache2-mod-auth-openidc-dbgsym_2.4.12.3-2+deb12u3_armel.deb 8d93c38ed543825b43b397ff1e062fe9 7936 httpd optional libapache2-mod-auth-openidc_2.4.12.3-2+deb12u3_armel-buildd.buildinfo 4285eee5b5ae1facb79efb02128ebb7f 176188 httpd optional libapache2-mod-auth-openidc_2.4.12.3-2+deb12u3_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEErcTbumGV7Ig2iXlfQdxRZ9J7nEgFAmf/xmIACgkQQdxRZ9J7 nEgmoA/+J/spof0lcSnsyrPsCTFR1d5po6+Znp0EUqSU4VIqG3z4eofsDQ/vXf4O F015FSanTGwACsJAvo/2VgVoyDIkBn5T2K9BHWrOedgbXrz8SMVPncYohQq3gKLG EvzS49ErNTkOXY0DiBjoWk7x1ZHU+NvLALtv7XjbmnP3Z4jVsOWeFql9cyDZR1Vm 4AopOmpmkgOYtZ/nM5Vb/ZzTLIKrchilIjm7fGwvsjj1sX8Ty9VNUPoOWi1smWbA Gioewa4J1l+JTZAnmaGSktn9mmbMSeIlpG3IE25ED/bUE1uOw+kBCNiZH4lYWEPg xzzvrzFMSIoOCiKDKZiCd/ibiXTKlkj56srXOkdlwNdOISDfDRmQqmvw7V/qV5Gm 0/CAaclqeuAvFKS/WQgFkelfTlCEMmIypYW+xzprXcrnoIqlUCaohe6iAB+Bp4DP FneQOAZe3fA7xAFTzmLbx17TMOn2AjBNsv5VHNYWE0wbwkgU+I6UtXIibT76GP3c aSY2jXI3bqOini5lYiCjNVlruPHYuwfBhvp8ioRC4R8k8Ml8aVQQQ1fWl87ckuHW UGd6q1qMZQEbbpdMppHNB32tFAmPthhOgKj93EaoAx68UBPzwCJkQEIW2Xa3MWV5 cXBbPWSXdB/MilAYn1K1gygTNwM5HAVo7/0/Ui0m6pe0pPb/eQs= =vsSz -----END PGP SIGNATURE-----