Debian Security Advisory

DLA-1410-1 python-pysaml2 -- LTS security update

Date Reported:
01 Jul 2018
Affected Packages:
python-pysaml2
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 886423.
In Mitre's CVE dictionary: CVE-2017-1000433.
More information:

Pysaml2, a Python implementation of the Security Assertion Markup Language, would accept any password when run with Python optimizations enabled. This allows attackers to log in as any user without knowing their password.

For Debian 8 Jessie, this issue has been fixed in version 2.0.0-1+deb8u2.

We recommend that you upgrade your python-pysaml2 packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS