-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Sep 2025 12:38:25 +0200 Source: shibboleth-sp Binary: libapache2-mod-shib libapache2-mod-shib-dbgsym libshibsp-dev libshibsp-plugins libshibsp-plugins-dbgsym libshibsp11 libshibsp11-dbgsym shibboleth-sp-utils shibboleth-sp-utils-dbgsym Architecture: mips64el Version: 3.4.1+dfsg-2+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Ferenc Wágner Description: libapache2-mod-shib - Federated web single sign-on system (Apache module) libshibsp-dev - Federated web single sign-on system (development) libshibsp-plugins - Federated web single sign-on system (plugins) libshibsp11 - Federated web single sign-on system (runtime) shibboleth-sp-utils - Federated web single sign-on system (daemon and utilities) Closes: 1114506 Changes: shibboleth-sp (3.4.1+dfsg-2+deb12u1) bookworm-security; urgency=high . * [80ae771] New patch: SSPCPP-1014 - Extend escaping in strings. Fix SQL injection vulnerability in Service Provider ODBC plugin: specially crafted inputs can exfiltrate information stored in the database used by the SP. The vulnerability is moderate to high severity for anyone using the ODBC plugin, and of no impact for others. Thanks to Scott Cantor (Closes: #1114506) Checksums-Sha1: f3df96a4701b0ec358f2b433835979e950a6ea9b 399152 libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_mips64el.deb 5f70cdc9272583b7b3ec9c78b8e9200fcdbd509a 63204 libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_mips64el.deb 7e93b435772c388efdd3ea429a4798195a8da783 54396 libshibsp-dev_3.4.1+dfsg-2+deb12u1_mips64el.deb 5c3b14a916593158bd0915d9efa8bc1e7ac84a4d 2381936 libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_mips64el.deb 071189ebde39fef5e96ab013f3c9097cf5b6ea10 158012 libshibsp-plugins_3.4.1+dfsg-2+deb12u1_mips64el.deb 640b9bb2fef3214e6d106c2f28def1121db42c1e 20589808 libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_mips64el.deb f799f46fe9f21cfd0f8b1b130b97c3087ee31993 795508 libshibsp11_3.4.1+dfsg-2+deb12u1_mips64el.deb 9bf49ee50a4ff44e7f9813c338a3540c23912021 425412 shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_mips64el.deb fd03d65e8807b1e6ea385da82695946ba7627712 78820 shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_mips64el.deb a066d9e3795283768ebd6cdb0751138975bfa9bc 11625 shibboleth-sp_3.4.1+dfsg-2+deb12u1_mips64el-buildd.buildinfo Checksums-Sha256: 839d5a621ff2b2582e3cac06bed49c92b478794f81741699abd55aa6579e869e 399152 libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_mips64el.deb 20a2714d3d3c6f5e96e74ee01914525e0eea26f0816019c42c0fa1cc3b0af6bc 63204 libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_mips64el.deb b5255cd3fcde266fd56829d5fb930881be2d12fec666bff84d29fb884d6823d1 54396 libshibsp-dev_3.4.1+dfsg-2+deb12u1_mips64el.deb e70b2416863b99cc91f397adf350bb8416bac1f2e2bef41b21330794a82605fc 2381936 libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_mips64el.deb b3307cba44ff68077552b554903b6e7384717d4d5e6b745065404eb85297414c 158012 libshibsp-plugins_3.4.1+dfsg-2+deb12u1_mips64el.deb 434100dd4a452403f2eb3d45c08a2f599280b719abd4a13c1bad6a1ebbc0915a 20589808 libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_mips64el.deb 2a25c1c177ac89befaf63e8bccbc4e894dbcfc0127c77c45f594439817324668 795508 libshibsp11_3.4.1+dfsg-2+deb12u1_mips64el.deb 527bd84c1e11215bda93e64968a2cd57a11d11b4311debde7bbbdf2a8b1c5be0 425412 shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_mips64el.deb 608384c114e165eed81cd45c96648089d733c9f39000a4dbf50e568595a9ad87 78820 shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_mips64el.deb c5be93f01066a319cb71b41a87d8ea1833dfd47c3a0832553f6c307cb2ca7d12 11625 shibboleth-sp_3.4.1+dfsg-2+deb12u1_mips64el-buildd.buildinfo Files: 626a0090e26683401cfad1081aac64bd 399152 debug optional libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_mips64el.deb 1a450b67bd1c6f57d0eac73f2af932a3 63204 httpd optional libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_mips64el.deb 7e065d5f1f583bf02fedd92a20ec6cea 54396 libdevel optional libshibsp-dev_3.4.1+dfsg-2+deb12u1_mips64el.deb 14dad4a7a4a8cbec3c5cae93187090f1 2381936 debug optional libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_mips64el.deb 357c37034b8885f09d1d466f1d016039 158012 libs optional libshibsp-plugins_3.4.1+dfsg-2+deb12u1_mips64el.deb 9439805ffaed8bdf152b6abc41c95e63 20589808 debug optional libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_mips64el.deb 3b383e03ab6a915c8e67c686372f9ace 795508 libs optional libshibsp11_3.4.1+dfsg-2+deb12u1_mips64el.deb 3bbeb8a81b906fef79b1df36dc0335d4 425412 debug optional shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_mips64el.deb c3b8ca45afa22bfc42e1d932b8aace2c 78820 web optional shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_mips64el.deb 1d6d1fdc09497b7cfbedb048790b3113 11625 web optional shibboleth-sp_3.4.1+dfsg-2+deb12u1_mips64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYLhEzFkGpb3yYRVHmlVdU6AM9BUFAmi8i4EACgkQmlVdU6AM 9BVIpBAAlpLBHUwXsc/6kICho0eU+2wkfO4FZ/7SkBQqbfYEXGU9cDjuuELMpBMW kwwaDvLdr3FlO5P2r6mu+ihxZp4Jc2SwLVmOKQLKGO9OFxGA7RL5GsgQ4IkrgHVw 6XaJGMtWzcmr+f9ZjxUZWDvRYNgVPoWyGk2r2CzIwzyF5kOWGCehpakjBSp7OXDu UsuEhBIYsJn/L7tLi0PznpAeOA2yuJLmi+AGrYCQRhyXeK9dmRwBPBvSRcBJ91tn 5Hc5DlWPCmYbWDqjjevjB9oQC6DQlefCX1NnEiumVcmwz6nip0fOdkFCyw7zAuhA TMBYH2ivCvjqWWwn+n5WOJ+Vlq0vsAJBmXEX0GAg1tCIIqJ/VqU69sK/NfcSLPIT 7hDOf2IFB4qIWY4pqyvV9yQp7WY/IJgjZfTZHWiALJKx0otcs9oeQzNb+Jmi2HN9 bel06J17j6qDLu9GvG/OGVfGKMsAHNU3jEidVl3BaXLnFdM0LUi5DYb6KwMO6+JM zGTGSX2ZOLyfw2SVQM3m1fHjV9RRhYFKpQ1oOt9tWeO3bOccS0nVaoA0uj/eX3eT foWYK8b/NKo29sxLU3OL2QOId9dtRxO/k55XqhJd430YgE4SIakOwhgHI4fKwboo 6YxbPNHWELTkasHHfn2i4oBmCcPEnEuBC684HGRVRtEOizCtWtg= =2Gtc -----END PGP SIGNATURE-----