-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Sep 2025 12:38:25 +0200 Source: shibboleth-sp Binary: libapache2-mod-shib libapache2-mod-shib-dbgsym libshibsp-dev libshibsp-plugins libshibsp-plugins-dbgsym libshibsp11 libshibsp11-dbgsym shibboleth-sp-utils shibboleth-sp-utils-dbgsym Architecture: armhf Version: 3.4.1+dfsg-2+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-06) Changed-By: Ferenc Wágner Description: libapache2-mod-shib - Federated web single sign-on system (Apache module) libshibsp-dev - Federated web single sign-on system (development) libshibsp-plugins - Federated web single sign-on system (plugins) libshibsp11 - Federated web single sign-on system (runtime) shibboleth-sp-utils - Federated web single sign-on system (daemon and utilities) Closes: 1114506 Changes: shibboleth-sp (3.4.1+dfsg-2+deb12u1) bookworm-security; urgency=high . * [80ae771] New patch: SSPCPP-1014 - Extend escaping in strings. Fix SQL injection vulnerability in Service Provider ODBC plugin: specially crafted inputs can exfiltrate information stored in the database used by the SP. The vulnerability is moderate to high severity for anyone using the ODBC plugin, and of no impact for others. Thanks to Scott Cantor (Closes: #1114506) Checksums-Sha1: da8e47b564cf371144b90a4c097b8ec1877402de 394888 libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_armhf.deb c1ff4345ed03cfe55691cea9f5438eb78977df3c 60584 libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_armhf.deb 9c163abbaf5abe874929f1994c0633591cfbdd28 54372 libshibsp-dev_3.4.1+dfsg-2+deb12u1_armhf.deb 37e651dbf53f05e0f1042e8a49ad5c62a94bb045 2409748 libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_armhf.deb 4d57e97dde675854bcc641f65a212bc032473e6a 153984 libshibsp-plugins_3.4.1+dfsg-2+deb12u1_armhf.deb d442c8ed3bcc67d5666e5a2f59b7697bd40c3e05 20733680 libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_armhf.deb eec80abd2b4bb21373791fee7e77ef753f0051cf 847976 libshibsp11_3.4.1+dfsg-2+deb12u1_armhf.deb 480109c720de9d53c654b8c26059600e008d3d87 423456 shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_armhf.deb 992da31cbadb91f3c68fddf538dc61adf97deec6 72972 shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_armhf.deb d6310445646eb6ddbe6ab3a956b618be55b43df3 11601 shibboleth-sp_3.4.1+dfsg-2+deb12u1_armhf-buildd.buildinfo Checksums-Sha256: 6f89e4094f6ec3134a58e66770bb27cce3ac58d2fd07d3517ce647f663d9e13a 394888 libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_armhf.deb 5b7f3399d5a52fb8aaebb845e06c3070451f49a055af4155aa0a31674f5cba94 60584 libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_armhf.deb ab91b4e89a4b3ecb383bcc4b0c02a11e9dd938652825f3d4d6f31e3f0c2c6902 54372 libshibsp-dev_3.4.1+dfsg-2+deb12u1_armhf.deb 6e3f64cf33672f484b1d6387873d49f23dd61fcda01c91eff8d337e6a7990bf9 2409748 libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_armhf.deb e6871573a5a095c3a0311742280576de33d95e9d8fd9aa70d338a62fe86db22a 153984 libshibsp-plugins_3.4.1+dfsg-2+deb12u1_armhf.deb b9d464d5438430701c3c8ddcec1935627eaee16be061c294688aafd3ac486b5b 20733680 libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_armhf.deb ca6112fdfb23ec1b33493a9f20512d3a162e1768032ffec349377ed110c92565 847976 libshibsp11_3.4.1+dfsg-2+deb12u1_armhf.deb 3e3ce8ace034b5e3fbcbba18c93e4e10581480926028b5c165a04439bbc9cbe2 423456 shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_armhf.deb 8af35de363ea0318f6f10c01746491d37d6c36a06c2f5b6b87987858b4705bcb 72972 shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_armhf.deb 211cf39d07d2dd59db46c11f7df1ef461996004ddd166cf8d4f2fccb0c0e9924 11601 shibboleth-sp_3.4.1+dfsg-2+deb12u1_armhf-buildd.buildinfo Files: 87d9d70d0217a4d38df168a816c4be84 394888 debug optional libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_armhf.deb 834bb11ef5723627760ed6e0cccdfc2c 60584 httpd optional libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_armhf.deb c649de2ea61b3b845f30140030365acd 54372 libdevel optional libshibsp-dev_3.4.1+dfsg-2+deb12u1_armhf.deb d5b9ef33f838086e7b163b2c7bae7a54 2409748 debug optional libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_armhf.deb 033316ffb382a07ace722fa7c9a71627 153984 libs optional libshibsp-plugins_3.4.1+dfsg-2+deb12u1_armhf.deb 12640dfd0b4f95789efe81e16aee15bf 20733680 debug optional libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_armhf.deb ed1177cbe193761e002f184b6f4a1ba9 847976 libs optional libshibsp11_3.4.1+dfsg-2+deb12u1_armhf.deb bd32184236d513745c2365fded4b3161 423456 debug optional shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_armhf.deb 17301de9e9694033338a36eb05ebc512 72972 web optional shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_armhf.deb 41c5fec51360bceed5c216627027d556 11601 web optional shibboleth-sp_3.4.1+dfsg-2+deb12u1_armhf-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEpxWVfktWxVoKRwGgJ7tNDw2WyRsFAmi8iTsACgkQJ7tNDw2W yRtGJRAA1NR2L33YSVuweZrFW9DHx94WibiIXG6D5d3ZDEVLmcYDjW/lfq2M8B3d raNgS3bg5+Z6bUWgWNNuf3upiDvIhDvzm7i4zIo7ylsERmyb8eIbt3cQz87RU5+/ 5snns0X5J4QPK6pwTSF9gA3XtavpGonxP00uJd3yPSGVhVWhBLuHSGdVFQrSq8Ab wB2Dclx9bNji5qpO72yCLaxJ2xyJU0d2Q2mzQHXm05EXLRODN88UYCQUnKzJMJU4 TbN9IW0CjD08J+nzpsBpZeXSaVf9+SK8cnsgvSIrz/XtIi6R2NcIIyXz1lVchwql ENWlU6QwFjybY+K+FhvbOfo8VBNkYiRR8/H3D+WVpStKgsQcuRBqAqSPt6nrPgEH plyPOaehLaVE5ZS0XPacfOcfV6WoO8KzJZKjxL6Xt7xVlOTAEb0hxBuHIoFvLjhP QH72HR3w+aDg8V1ovlReEYoiuf7KdgWps3n0t90OtXkoISW5VgJ9kKgT81PrLnmb KEm4hjk9fSRL8PZd62zO8LohRYpi2I/WSpd8pP3z/15ACr/YFzMokgk1Lr09WqHD N6bGH70Buy8aTbjKR+BgsF9U3ZBpkQSBbr7JovHL5PpOVWvzEINmsnIkEEROtiOM sorXqs2jjAy9c/embvBfb428ehQdmildB9u04J+AChuEINS6pbY= =XpqY -----END PGP SIGNATURE-----