-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Sep 2025 12:38:25 +0200 Source: shibboleth-sp Binary: libapache2-mod-shib libapache2-mod-shib-dbgsym libshibsp-dev libshibsp-plugins libshibsp-plugins-dbgsym libshibsp11 libshibsp11-dbgsym shibboleth-sp-utils shibboleth-sp-utils-dbgsym Architecture: armel Version: 3.4.1+dfsg-2+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Ferenc Wágner Description: libapache2-mod-shib - Federated web single sign-on system (Apache module) libshibsp-dev - Federated web single sign-on system (development) libshibsp-plugins - Federated web single sign-on system (plugins) libshibsp11 - Federated web single sign-on system (runtime) shibboleth-sp-utils - Federated web single sign-on system (daemon and utilities) Closes: 1114506 Changes: shibboleth-sp (3.4.1+dfsg-2+deb12u1) bookworm-security; urgency=high . * [80ae771] New patch: SSPCPP-1014 - Extend escaping in strings. Fix SQL injection vulnerability in Service Provider ODBC plugin: specially crafted inputs can exfiltrate information stored in the database used by the SP. The vulnerability is moderate to high severity for anyone using the ODBC plugin, and of no impact for others. Thanks to Scott Cantor (Closes: #1114506) Checksums-Sha1: a1725ddf92257a86b29538546c8817d3bb45ffe1 393748 libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_armel.deb b56e5d929c31e4ac9a14078f0159c3fbc249237b 59152 libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_armel.deb 2249e4233f3687640de2e8337a99a38edee6fc27 54392 libshibsp-dev_3.4.1+dfsg-2+deb12u1_armel.deb da066b720ff01809e2e64dbc8afe8b0290cc9031 2407600 libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_armel.deb 26da2bded956fae3aac1ad78a5daeb258401a0ca 149460 libshibsp-plugins_3.4.1+dfsg-2+deb12u1_armel.deb 065de75545c66d0c7fe0d1ca730db32ce65dcfd6 20728928 libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_armel.deb fc35a674c5b07ba8d677f77ddfd927018dc21bd1 817088 libshibsp11_3.4.1+dfsg-2+deb12u1_armel.deb 46c7a1ef897d209e5f775b47c515ddd47e766ea3 422352 shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_armel.deb f134d9e4b35ed57809188c9aee7424e56d20f6db 72152 shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_armel.deb 94fff32083d17ac1e6caa6abf7ee57140d12727a 11599 shibboleth-sp_3.4.1+dfsg-2+deb12u1_armel-buildd.buildinfo Checksums-Sha256: a885a4b4b8b2d5ef89a167e18ba59943b0f867d4a79397b63b7c4741183dc589 393748 libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_armel.deb f3bf52ea8faa2f2cdd8e168b8c620c13f86544d81076bd8e04c0d818dbac6559 59152 libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_armel.deb 465ed40b524685ab8570d4527c7b11a9ae4bb85099bc51550933c8fcad955378 54392 libshibsp-dev_3.4.1+dfsg-2+deb12u1_armel.deb 837455632fd6ea1e54fefe8c90f1599363f1592943b478535b1fe817fb2d05cd 2407600 libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_armel.deb 60066c0107ec9fd907a874d9e39ee75b472625722cd5626adee558dbc0357788 149460 libshibsp-plugins_3.4.1+dfsg-2+deb12u1_armel.deb 7dee2d6098d1413be1e8559c2ad37d96333c1cbe50a527fd08ca377972b08046 20728928 libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_armel.deb ebdbb7715f1bf6af22aeb76b2f3d21368d9c263dc85601f9e59bf3e4252c8143 817088 libshibsp11_3.4.1+dfsg-2+deb12u1_armel.deb de32e6c8585a197218afead5a54f3b891166bfee04b5f6802b0cbdcda18d2a8b 422352 shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_armel.deb 4371f00a3b6bdd4e2e871342772eaecd59e1d506c4ab24f607c976d03cfdc99f 72152 shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_armel.deb 00ab342895df5c9406c4a190c642f7ddd17feeb204afeb3639fc8462b851dfb6 11599 shibboleth-sp_3.4.1+dfsg-2+deb12u1_armel-buildd.buildinfo Files: be62f79a4f072129d17197d459d3d118 393748 debug optional libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_armel.deb 8db23f0b1a4a7fe9ebdbd58b27bc4255 59152 httpd optional libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_armel.deb 6d2139df30dd395793e2bfe308f18589 54392 libdevel optional libshibsp-dev_3.4.1+dfsg-2+deb12u1_armel.deb 8827b04cb0937064c58cb2974956591d 2407600 debug optional libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_armel.deb 761774433171837f6c3c3526789593d6 149460 libs optional libshibsp-plugins_3.4.1+dfsg-2+deb12u1_armel.deb 1f8ac47722f913256decb1c945b6972d 20728928 debug optional libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_armel.deb 2a2e5faf25c9366f88bac8ffb79d7572 817088 libs optional libshibsp11_3.4.1+dfsg-2+deb12u1_armel.deb 14192d531e824c6ac3c19d31e58b0ff6 422352 debug optional shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_armel.deb acd0a29fc01846294ea4a4909d98689a 72152 web optional shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_armel.deb a3a687ffcb7f29d5e2fdc883646bb4b3 11599 web optional shibboleth-sp_3.4.1+dfsg-2+deb12u1_armel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEWHj9K9pO9l4btbD1OQKMdMnEH5MFAmi8h6oACgkQOQKMdMnE H5M56RAAq3F1IajiivdxLleO/LvKToePQ18M5MxHTerYajdMLjHZ+qgTVHVbB281 cwewUCN5O6TikTxKSTOq6xz4v094NCVHrWFw2NCRFEvBYW0csQXyZIXlfnkPWWoV gVlmvruRMPvc0xqhbcUbhOZyDfMsYUvfd+oVDqEJlkx1VT/YS+GFTLXtKTvX8SQZ owtF/E8pb6VAkrwTboNjxUeKpDwwbXC7zccdFQsIoip5EpTx4ABgX2duVbo85IoF HML3z10fK+GvPxa+sFizfeF5tikAIYKeBRmlfcg2mRhCbZfyxaoCgWxWwot0B7yX JxlQr5STaKYgl8V5zTM+PAvIUx3I+M/oisQnjUaQ4SWkuuLXguABV0D7bqITzIdF pfR94mpDeAaObbKN/9E8q5JpVOFPVyEPAzElM1+fFztveTsaqAgive6W47up3Tji LzMa2okhrlNpNy4nBqgj3ZirynR2dRAQ0uKoIs4Tx+APMOH+yEpP/5+aGfjoJUDY 6gntG+WBpoYp2xyqfTXNmhoT41Le/T7YsVwy6c7KINABL9KsSR2MAbF0+xFewuV5 9EuFwD6cuVKEMD7gzFqu8lkirSa0QdF62v0IUWz1lsqsC39QI09OTIAGIclNPAe2 2EQwbouRIKMU2yUiOkxGsOZJsow1wp9vIoHvqNQg4adgh+sN7fQ= =JD9T -----END PGP SIGNATURE-----