-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Sep 2025 12:38:25 +0200 Source: shibboleth-sp Binary: libapache2-mod-shib libapache2-mod-shib-dbgsym libshibsp-dev libshibsp-plugins libshibsp-plugins-dbgsym libshibsp11 libshibsp11-dbgsym shibboleth-sp-utils shibboleth-sp-utils-dbgsym Architecture: mipsel Version: 3.4.1+dfsg-2+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Ferenc Wágner Description: libapache2-mod-shib - Federated web single sign-on system (Apache module) libshibsp-dev - Federated web single sign-on system (development) libshibsp-plugins - Federated web single sign-on system (plugins) libshibsp11 - Federated web single sign-on system (runtime) shibboleth-sp-utils - Federated web single sign-on system (daemon and utilities) Closes: 1114506 Changes: shibboleth-sp (3.4.1+dfsg-2+deb12u1) bookworm-security; urgency=high . * [80ae771] New patch: SSPCPP-1014 - Extend escaping in strings. Fix SQL injection vulnerability in Service Provider ODBC plugin: specially crafted inputs can exfiltrate information stored in the database used by the SP. The vulnerability is moderate to high severity for anyone using the ODBC plugin, and of no impact for others. Thanks to Scott Cantor (Closes: #1114506) Checksums-Sha1: a1f469768d6ebe0f843d7690adf60d9152b44976 392860 libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_mipsel.deb 1fe2c8192733afd3fa9a78a9d9dc51bc73273bc5 63076 libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_mipsel.deb f7b391fa32c94dee25f73bf930622043045841f8 54372 libshibsp-dev_3.4.1+dfsg-2+deb12u1_mipsel.deb fd4a179edfbbcf6335ae06e7201c74c0031cb29f 2326992 libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_mipsel.deb b84bd5952ea28a8958bc080d5909e6521b0d7a13 158416 libshibsp-plugins_3.4.1+dfsg-2+deb12u1_mipsel.deb 99d5f1a98c95bb4ad660893561ddadb931190dae 20173936 libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_mipsel.deb 9e3827eb70c2f3b9a1ff00e055ce3a6d56aeee2d 796760 libshibsp11_3.4.1+dfsg-2+deb12u1_mipsel.deb fa2392dfd5b562739e53000ae8da9770db5298b1 418936 shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_mipsel.deb b9f654ea2280d24fa60938ecfd81b4496276bc08 77708 shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_mipsel.deb 6689cff9e952bb3b8f7bac413cdebbf0253fab13 11560 shibboleth-sp_3.4.1+dfsg-2+deb12u1_mipsel-buildd.buildinfo Checksums-Sha256: b6516dc87fdc19349fe6cd17b2793c62bac09b4921cd05b757b29b1374b4863c 392860 libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_mipsel.deb 25761b8565eb1816852b09ca81e67a6276112abba1adf247f700997248766327 63076 libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_mipsel.deb 91de200fae48f53e4a237698334b43bb6151043483eb84712a16b937e7dad769 54372 libshibsp-dev_3.4.1+dfsg-2+deb12u1_mipsel.deb 86bccdd7585a47d9b9f310f1a94b5609be587cb9302aef0c2c29a29d82a8fa22 2326992 libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_mipsel.deb ec2bb5c9b26e90c73f0d43aac530ed3c5584ac7409f77e487a586b5487d30f78 158416 libshibsp-plugins_3.4.1+dfsg-2+deb12u1_mipsel.deb f2a23e56555565c8ed7b5087b8dec26ff4239f2a139454f22f431c15ea037829 20173936 libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_mipsel.deb 3de614125c962fbfea55b541fbc5ccffc24fbc40bccf078d60ac08d0e9b7deeb 796760 libshibsp11_3.4.1+dfsg-2+deb12u1_mipsel.deb deed1664285371c0bcf46d35acf8d874311da6662741e9ee8018d9e95182be74 418936 shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_mipsel.deb 6fe21b43eb07dfaea252f2d29b52a670127c09ad998120327e39d9abb50f183d 77708 shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_mipsel.deb a6d447607710a9a3a3095d05228b941f2d73fdac6f541fcb63851debcb55a677 11560 shibboleth-sp_3.4.1+dfsg-2+deb12u1_mipsel-buildd.buildinfo Files: fb3f2997748664a7235e39a4351be53f 392860 debug optional libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_mipsel.deb 8187b8d17622be9164378671e4ea1a9d 63076 httpd optional libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_mipsel.deb b3774022ce77b3af94c8f3131d546caf 54372 libdevel optional libshibsp-dev_3.4.1+dfsg-2+deb12u1_mipsel.deb 27c703c9a709e9beb8efd2c06406ebb1 2326992 debug optional libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_mipsel.deb e512f5b61d67ebce68116b95bab45d45 158416 libs optional libshibsp-plugins_3.4.1+dfsg-2+deb12u1_mipsel.deb d9f0a42c9ca517d8ef0a7401f9346a82 20173936 debug optional libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_mipsel.deb 82bd44aaa7e42698de8bbda11031cf02 796760 libs optional libshibsp11_3.4.1+dfsg-2+deb12u1_mipsel.deb 48b170af322ef61df1cb76486ada9507 418936 debug optional shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_mipsel.deb 967c24ad3da87c69996614858962809f 77708 web optional shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_mipsel.deb 8b62c4392e707a5a8bf5da6ba120a0a8 11560 web optional shibboleth-sp_3.4.1+dfsg-2+deb12u1_mipsel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYLhEzFkGpb3yYRVHmlVdU6AM9BUFAmi8iQQACgkQmlVdU6AM 9BVhpg/+L3i8p9xekCkjfi9CMtoz8jyaFYGEPTwJVtdHR/YATvKnM94JI2IiHRqD x0179bKwyO4ZtYcRPT1jc/g4XyWVs/qKgnuaXzeVJcLx0JVdcJSg29Zjm/J8xzaa SvYJM4N5BzcQVAj60cMJbGkzHrFwLdz0bgPmoG25CFBH33EM8S0/L8Bwoc1yitpB Vlhn4n/c6ztUXMD8H8Ubr2DGkR+IiEM8qCxlhSZAZ+lwauWsfIIKSM75+TuxEvxJ SdtFWGyTxW1lV1pVy9f3D7GOCMtiUYz3hnGehJOK/sRQ7GOO0mILnCC1GhR2Mn3F wrwk5k693jo7wFlZsGr/rpeqszVkr1EUcPWLR+Se47WUbqCoOtyYSNVVh+Fpc1hb zNz1eE56aWf+3C3sKWPssqltlOv0eTKBHgoqnI4e6wZMUIDVhmm8SXQ3XFP4i+8L 62tXc9JOWytcPCnu0EE8/EPlI/ZsCvUjf5rcbNRRp84Jb/5hW9MjIPynMBwiKYYe A/Nf/HRp9NjfHcep66+z9eoK5u88rhUm2RfXdvnABlY1p+JXwkVZL50seGt8KfJP eVx1qnqkX5lI+yI5aS7b9+uaGofbBjfe71KFGyQBuhJKId5Rp1w2wcxbwlSkXeiQ cEivMMq8GgFTzFlV4aUpJpqegnf0tFHJiQVjWI9+vB1Mp/zjR7U= =arHp -----END PGP SIGNATURE-----