========================================================================== Ubuntu Security Notice USN-4974-1 June 02, 2021 lasso vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.04 - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Applications using Lasso could be made to allow unintended access. Software Description: - lasso: Liberty Alliance and SAML protocol Library Details: It was discovered that Lasso did not properly verify that all assertions in a SAML response were properly signed. An attacker could possibly use this to impersonate users or otherwise bypass access controls. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: liblasso-perl 2.6.1-2ubuntu0.1 liblasso3 2.6.1-2ubuntu0.1 python3-lasso 2.6.1-2ubuntu0.1 Ubuntu 20.10: liblasso-perl 2.6.0-7ubuntu2.1 liblasso3 2.6.0-7ubuntu2.1 python3-lasso 2.6.0-7ubuntu2.1 Ubuntu 20.04 LTS: liblasso-perl 2.6.0-7ubuntu1.2 liblasso3 2.6.0-7ubuntu1.2 python3-lasso 2.6.0-7ubuntu1.2 Ubuntu 18.04 LTS: liblasso-perl 2.5.1-0ubuntu1.2 liblasso3 2.5.1-0ubuntu1.2 python-lasso 2.5.1-0ubuntu1.2 python3-lasso 2.5.1-0ubuntu1.2 After a standard system update you need to restart applications that use Lasso to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4974-1 CVE-2021-28091 Package Information: https://launchpad.net/ubuntu/+source/lasso/2.6.1-2ubuntu0.1 https://launchpad.net/ubuntu/+source/lasso/2.6.0-7ubuntu2.1 https://launchpad.net/ubuntu/+source/lasso/2.6.0-7ubuntu1.2 https://launchpad.net/ubuntu/+source/lasso/2.5.1-0ubuntu1.2