Bug#868466: php-cas: CVE-2017-1000071

2019-02-08 Thread Moritz Mühlenhoff
On Sat, Jul 15, 2017 at 09:06:41PM +0200, Salvatore Bonaccorso wrote:
> Source: php-cas
> Version: 1.3.3-1
> Severity: important
> Tags: security upstream
> Forwarded: https://github.com/Jasig/phpCAS/issues/228
> 
> Hi,
> 
> the following vulnerability was published for php-cas.
> 
> CVE-2017-171[0]:
> | Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass
> | in the validateCAS20 function when configured to authenticate against
> | an old CAS server.
> 
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

Fixed in 
https://github.com/apereo/phpCAS/commit/c9ba00327fd0ac8faecc62ce150c1986022856cd

Cheers,
Moritz



Bug#868466: php-cas: CVE-2017-1000071

2017-07-15 Thread Salvatore Bonaccorso
Source: php-cas
Version: 1.3.3-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/Jasig/phpCAS/issues/228

Hi,

the following vulnerability was published for php-cas.

CVE-2017-171[0]:
| Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass
| in the validateCAS20 function when configured to authenticate against
| an old CAS server.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-171
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-171
[1] https://github.com/Jasig/phpCAS/issues/228

Regards,
Salvatore