-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Sep 2025 12:38:25 +0200 Source: shibboleth-sp Binary: libapache2-mod-shib libapache2-mod-shib-dbgsym libshibsp-dev libshibsp-plugins libshibsp-plugins-dbgsym libshibsp11 libshibsp11-dbgsym shibboleth-sp-utils shibboleth-sp-utils-dbgsym Architecture: ppc64el Version: 3.4.1+dfsg-2+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Ferenc Wágner Description: libapache2-mod-shib - Federated web single sign-on system (Apache module) libshibsp-dev - Federated web single sign-on system (development) libshibsp-plugins - Federated web single sign-on system (plugins) libshibsp11 - Federated web single sign-on system (runtime) shibboleth-sp-utils - Federated web single sign-on system (daemon and utilities) Closes: 1114506 Changes: shibboleth-sp (3.4.1+dfsg-2+deb12u1) bookworm-security; urgency=high . * [80ae771] New patch: SSPCPP-1014 - Extend escaping in strings. Fix SQL injection vulnerability in Service Provider ODBC plugin: specially crafted inputs can exfiltrate information stored in the database used by the SP. The vulnerability is moderate to high severity for anyone using the ODBC plugin, and of no impact for others. Thanks to Scott Cantor (Closes: #1114506) Checksums-Sha1: e7e21fc558ec2721b079c7c74fd74b02209261a4 396920 libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_ppc64el.deb 4d9f649cf61a454533ac56fcd58acc9209c46748 68116 libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_ppc64el.deb e4b49ebc4c574b4a0ef9dcef2ca3312f9cf9cd01 54400 libshibsp-dev_3.4.1+dfsg-2+deb12u1_ppc64el.deb 979791f5f75c5d13462dfca5eacfbe05024bc985 2381352 libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_ppc64el.deb 7ffccca90bc0037f14a4cc84e8bee87e9f0050cc 174164 libshibsp-plugins_3.4.1+dfsg-2+deb12u1_ppc64el.deb 7323245e9d0998cd25512b9aaa9ede7a78bc5c04 20567272 libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_ppc64el.deb 9c6231458afe9b85cdbd1b63551efeb0d6d26651 966980 libshibsp11_3.4.1+dfsg-2+deb12u1_ppc64el.deb f312fe382eb3c0cce4a12f89f0fe0f5897f51368 422680 shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_ppc64el.deb c3901720b970117421bdb182241ea7a271013c84 80112 shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_ppc64el.deb 46753f4f2f81bc891ce413a00f5b0c178b653abe 11796 shibboleth-sp_3.4.1+dfsg-2+deb12u1_ppc64el-buildd.buildinfo Checksums-Sha256: 2d1c9ebfac9446f09ffaf19082ea0430228358f3817b24331c0fea952d0e6aeb 396920 libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_ppc64el.deb 23d7835d5dfc99f9644847e2726062742c960f1ce777dd0e5bdaffc98471a3b8 68116 libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_ppc64el.deb 8352dfa995bc4f27d1a23e4bd8c36d4d453de311f7505549bca8c4b817aef30a 54400 libshibsp-dev_3.4.1+dfsg-2+deb12u1_ppc64el.deb 0cd5a3d6db49a8477e9d47031a5403471bbe63fc4f25e187fe5979cdd12ff912 2381352 libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_ppc64el.deb 3ed01848bbcc30095f8f14e6e600e2d6e41ab2f36f2ab84340bc8fbd043ec0fd 174164 libshibsp-plugins_3.4.1+dfsg-2+deb12u1_ppc64el.deb c79065d7e708bcc2eceec73e878279ac8c4f91222214b51563a1bc5a4c77ff37 20567272 libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_ppc64el.deb 7476ad3f86d80c69fce5371a4d550a269d76a68fe054fe5c5f56af83067073c3 966980 libshibsp11_3.4.1+dfsg-2+deb12u1_ppc64el.deb 8f4612056ef34a1550df9d08e7b1b1f93d79c57eb854ae84bdf11d750200acca 422680 shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_ppc64el.deb acbec93386c5867db3e2146f49bb457341249c6fccfb2f94c79bc06f65791bae 80112 shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_ppc64el.deb a128f84bae3ccd80d2c00a61a6b6ea5b4fb56c43675d663dccc1177a337ab35a 11796 shibboleth-sp_3.4.1+dfsg-2+deb12u1_ppc64el-buildd.buildinfo Files: 28bdf41215975c3a8f97f5caa497f574 396920 debug optional libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_ppc64el.deb 942c591d75ccb141a45b58b2a23d710b 68116 httpd optional libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_ppc64el.deb 194ed4ed01445faa5a793e624673e2d7 54400 libdevel optional libshibsp-dev_3.4.1+dfsg-2+deb12u1_ppc64el.deb 44f869ab9b92b00c6eb42842fb082ccd 2381352 debug optional libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_ppc64el.deb 6900710df79369ceca8b8d4c50c2506e 174164 libs optional libshibsp-plugins_3.4.1+dfsg-2+deb12u1_ppc64el.deb 26dbb61c0f99f3cbcf87e5c5c752e63e 20567272 debug optional libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_ppc64el.deb 51a27ac14731f2a47390d6d948416c22 966980 libs optional libshibsp11_3.4.1+dfsg-2+deb12u1_ppc64el.deb 53074cddc45897b37a6fa16968cdec51 422680 debug optional shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_ppc64el.deb cb410d2baeca8d015bc1eb6386f3596e 80112 web optional shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_ppc64el.deb ef7a5b1c0e4e97c8c846c18f3185ea34 11796 web optional shibboleth-sp_3.4.1+dfsg-2+deb12u1_ppc64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvNkWZvjZkiWgJGRETMSrGPLkYxUFAmi8hycACgkQTMSrGPLk YxXpqg/+LSn4CRItKx6T5spIWPBHFRKUnj5VsNWFUeFRgbN6sLGtNArshvu+o7bf J962rrBXGPQC0MC1xiz22cgBi0ijUBE1tAT5tpEHdkD+ZEuJzm1c075nZWSeugCz JVGVH36IYwJ5kL24ERsUcuYg1Rqca65xjJKpFYXCPVen2eyZFCIexDpqMw+ZUyLk D2i5w01lqlvdTZEC4YMr8q5alUVMVwgHOULoc9C2L0LNeffuhrxLX4XZByTRnz0z L2UptFY9eRHQNCsAaESQJe1XSetU2xGyqCS31gKITN01pdfa9PPQ1rj+8gmmp0jD y8jUzKQ6ZlO9XSXG9bpRUQ6O9+pnB0zJkAffdkNgP/md/xA1lYcyDr5//7gIs8fb 4K26MSMljlOG0y+ro+PuQiNFNpB9efh7uDuxFlZoKxRlfo7Wbsz55s8VP88/kln3 /2RxKKgCmHAs24roJIJU+nrSGfQbnMUiKY65XaAWyBk/atgFWqzc9FUXDT2C/K91 BfI1I9dbII+Z5n5qujJ0Ehb9Yko9+sd7gR0urWDovvIfvVJlonTJwH+a2/q04esS Cy/2o4FmprkDy0EwTmlW9sGP2YZwntoGs20aBqvqku3SI/qLJFj/XuP8BSxYmaYg Myu7KXzBU5/nR8sSm0Tf4XlgP5Y/laNfInJD+NGxLVEUKX7QbJI= =y/c6 -----END PGP SIGNATURE-----