-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Sep 2025 12:38:25 +0200 Source: shibboleth-sp Binary: libapache2-mod-shib libapache2-mod-shib-dbgsym libshibsp-dev libshibsp-plugins libshibsp-plugins-dbgsym libshibsp11 libshibsp11-dbgsym shibboleth-sp-utils shibboleth-sp-utils-dbgsym Architecture: arm64 Version: 3.4.1+dfsg-2+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Ferenc Wágner Description: libapache2-mod-shib - Federated web single sign-on system (Apache module) libshibsp-dev - Federated web single sign-on system (development) libshibsp-plugins - Federated web single sign-on system (plugins) libshibsp11 - Federated web single sign-on system (runtime) shibboleth-sp-utils - Federated web single sign-on system (daemon and utilities) Closes: 1114506 Changes: shibboleth-sp (3.4.1+dfsg-2+deb12u1) bookworm-security; urgency=high . * [80ae771] New patch: SSPCPP-1014 - Extend escaping in strings. Fix SQL injection vulnerability in Service Provider ODBC plugin: specially crafted inputs can exfiltrate information stored in the database used by the SP. The vulnerability is moderate to high severity for anyone using the ODBC plugin, and of no impact for others. Thanks to Scott Cantor (Closes: #1114506) Checksums-Sha1: 6404de54f290207fb23ccfde97f780914763226c 391716 libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_arm64.deb bc2127d7c0049dcea10c61c483a710c3ed60c64e 62396 libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_arm64.deb c3bbd0f52a3c67992a199bff93f1dd9304718ed0 54388 libshibsp-dev_3.4.1+dfsg-2+deb12u1_arm64.deb edc4fda70e9664a37dc990debdf44f6c24a3ae8a 2370568 libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_arm64.deb adc40ce243f22985032e826ff919bea0a4bb9be7 159232 libshibsp-plugins_3.4.1+dfsg-2+deb12u1_arm64.deb 0131f85bfd3c802fcf40734e665cf3a153c69ce4 20597884 libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_arm64.deb 3d2e7394635676646b4967eb35b078398ad5688a 865868 libshibsp11_3.4.1+dfsg-2+deb12u1_arm64.deb b04e4d2e26f33a2125a8b326a7a16660ce6aa5e8 422656 shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_arm64.deb b02a7d68e62090d0411ac076c96b0d00ad51c163 76528 shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_arm64.deb 743e2983c70f52a6d8a13c95308be08b2f3fe43e 11757 shibboleth-sp_3.4.1+dfsg-2+deb12u1_arm64-buildd.buildinfo Checksums-Sha256: 1919fac65f09828dca88a411809f6f002679959a827fd10f04b2702cb1a58331 391716 libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_arm64.deb 2017b12d20cef3138acaa90a2839b6d508d3d57b6cf3241eda5c66a133622b8c 62396 libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_arm64.deb 8346a684f3b472b417b137d21a975626020f18c6fd809c51591cfb55e038a02f 54388 libshibsp-dev_3.4.1+dfsg-2+deb12u1_arm64.deb 47c678082dc03d47da3bde8bf194b1a248bd633dc92623587b7b28059f5e9daf 2370568 libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_arm64.deb 6e8eee19099690196bc17b1533803028e243fdc4796348ec5fba096368e9da50 159232 libshibsp-plugins_3.4.1+dfsg-2+deb12u1_arm64.deb a0ee3ae856c16f6603709846e04884b736553f328d835f63fc7e16f3f328a5ad 20597884 libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_arm64.deb 2aee4f7f590a7a8fa87a3557c68adaa15c305733d0f07579d4fef675e38ceff2 865868 libshibsp11_3.4.1+dfsg-2+deb12u1_arm64.deb 384b15fa0fdc33e5e4ad74ee690c4e2a4031e305a6653614c0870151999a4d50 422656 shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_arm64.deb 912e987f23b983392ae59fbb0fc19cb3b187feeb546de4bee52f6a1edc2951e2 76528 shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_arm64.deb 421e2f95c6509d31f865d467e58927a6e1c2f3e163a5ee088839b5ed0643a148 11757 shibboleth-sp_3.4.1+dfsg-2+deb12u1_arm64-buildd.buildinfo Files: 78326f3ddfe88532452696a002fc7250 391716 debug optional libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_arm64.deb 3b8e1a041cc00aaad8424fb565aff4ff 62396 httpd optional libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_arm64.deb 61061d07b207b33fb78c2fedae1cd327 54388 libdevel optional libshibsp-dev_3.4.1+dfsg-2+deb12u1_arm64.deb 57c74d1356fb57b5e0382e35ce75cf20 2370568 debug optional libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_arm64.deb 5e5f86b1962266a235785a52828af4ca 159232 libs optional libshibsp-plugins_3.4.1+dfsg-2+deb12u1_arm64.deb 73b4327b201a3f55c4e1b7c2f1cd0bf0 20597884 debug optional libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_arm64.deb 0c965a9be1058d393eb960ee40a02863 865868 libs optional libshibsp11_3.4.1+dfsg-2+deb12u1_arm64.deb c7cf9070da915ac10390631ab0304b8f 422656 debug optional shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_arm64.deb a8ed1084f080629e52414ab7e8bf8a87 76528 web optional shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_arm64.deb 2d8def8db70438f4964615cb9707599f 11757 web optional shibboleth-sp_3.4.1+dfsg-2+deb12u1_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEWHj9K9pO9l4btbD1OQKMdMnEH5MFAmi8iHUACgkQOQKMdMnE H5Pz3xAAzDMs5kMokka5Bwf0BgoK7eJpKgh/m3UztW+4O/OSTsVqc8JNorMKlZZG ubsKb+HWvHLzb0OFKTC2JT36eycP+jOt/jTYcBudr1vVkihfBlqLmZ9Gtr/zs4ht /djmN1VIcwEO4uUJ74/irv/+TsCKYFpB84JulucfXyRbs7Ou72vxd0Xu+Q9qXDXU 67ZC1LmwWkDqOcdSCkDGFFGe+ffznhu+8N1dhceX+YBr0YCgmI2aWS4hytCQnkOV WWDkBNMThOsqV8ygPjRFZwwJYcEQ+nf3ngPpOns4wFXsXTa1lhlXnvwmZQo7Auvg 5ez/vjgEEZJqKl8V6I2h7SlYtPqJhEQAArj8xoKevHh4BkZSG5ZhvhWel6cefS7r H2ee/FyYHdJn23hNfFbzSB+Rx9JTtW2PEdXHl/OPrVbfUkey5iucznrLRFTUIh1a h0ezO3aS38cm5jzwCPydE8SJ0aLCCd7Xa65pTyw5jolFt56qbd9GzWGVG28hkv+f tWhfFXZJYolbhKfsmBkm3sAyFAj59Bh5NYyCLujUQgVvk2nJ3boMskp0bdv39qNR VmRrPsklxajUprs9fRb+TPCJO76a/1t1BEgrq2LaL6RHz0T6U3CGnWG33NYOX7wH BoDpfl2My6+wqsJ1pWhFIh60+7Rh0C9HJh5FH82JBcmUkRxOp2g= =OnwD -----END PGP SIGNATURE-----