-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Sep 2025 12:38:25 +0200 Source: shibboleth-sp Binary: libapache2-mod-shib libapache2-mod-shib-dbgsym libshibsp-dev libshibsp-plugins libshibsp-plugins-dbgsym libshibsp11 libshibsp11-dbgsym shibboleth-sp-utils shibboleth-sp-utils-dbgsym Architecture: s390x Version: 3.4.1+dfsg-2+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: s390x Build Daemon (zani) Changed-By: Ferenc Wágner Description: libapache2-mod-shib - Federated web single sign-on system (Apache module) libshibsp-dev - Federated web single sign-on system (development) libshibsp-plugins - Federated web single sign-on system (plugins) libshibsp11 - Federated web single sign-on system (runtime) shibboleth-sp-utils - Federated web single sign-on system (daemon and utilities) Closes: 1114506 Changes: shibboleth-sp (3.4.1+dfsg-2+deb12u1) bookworm-security; urgency=high . * [80ae771] New patch: SSPCPP-1014 - Extend escaping in strings. Fix SQL injection vulnerability in Service Provider ODBC plugin: specially crafted inputs can exfiltrate information stored in the database used by the SP. The vulnerability is moderate to high severity for anyone using the ODBC plugin, and of no impact for others. Thanks to Scott Cantor (Closes: #1114506) Checksums-Sha1: 4530b313bede10d746669c6c96606872dff0eba1 391856 libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_s390x.deb 3ed415a883ae6f76c0b7d399ac2510d56021ed7c 62912 libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_s390x.deb a03f1746d18a0e91c32f41fdf336e6c129d0f227 54396 libshibsp-dev_3.4.1+dfsg-2+deb12u1_s390x.deb 828f9ad066fa5de19af9e7f1a7e87714bdf4251e 2349960 libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_s390x.deb 6a9e0c701cc435885ae75d463cb6257460baba5b 160336 libshibsp-plugins_3.4.1+dfsg-2+deb12u1_s390x.deb 002ca959516a23271d8be94912210d033a71bb10 20430168 libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_s390x.deb 31bc9e25e04b0121875f555d21c730996f6597a0 864672 libshibsp11_3.4.1+dfsg-2+deb12u1_s390x.deb cce72a101a58d86a65430ccfe0226e411564d78f 420404 shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_s390x.deb 0f0b0ba19e38482e614027a6d2a4168ea704af36 75468 shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_s390x.deb 9e138459995fade3bd99efee50da954b6bef00d0 11645 shibboleth-sp_3.4.1+dfsg-2+deb12u1_s390x-buildd.buildinfo Checksums-Sha256: e91fc6111ae094c7befd2765c29621484dc060f4be10b015f2d2ae0fef6134a0 391856 libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_s390x.deb f5ca92968d22ef63baa9d751c63206eb90843565a48e2d5b75500e001b109071 62912 libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_s390x.deb 47947c83e6bf37929257676a0e3466828b58a0386afc2f5480e7130a178562be 54396 libshibsp-dev_3.4.1+dfsg-2+deb12u1_s390x.deb e917bb5a490b6f1955c614a5ed35d1af6ae93205588e730568723054f15d1964 2349960 libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_s390x.deb e61b135c05e4be0425a6b9f8517fa6149bd559f15daec52855b45b830a8716fd 160336 libshibsp-plugins_3.4.1+dfsg-2+deb12u1_s390x.deb c6a521d6c7a10c11d9fd65aa612cba83776ddbcc9b3092bc521759f5b0925d58 20430168 libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_s390x.deb 1b57383f5044165ce40726490f39ca4b478420dca8ea5c1206d98b1dd761e6dd 864672 libshibsp11_3.4.1+dfsg-2+deb12u1_s390x.deb 4d9a34848e9f614b50cec0cd5ebb428fe4060c8e6462d8af26f615f2eaf7c2c2 420404 shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_s390x.deb 07b579f438af9545f255a87b2dbda793731cd879b62045b196eae609c840622c 75468 shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_s390x.deb 5f4894879d8c5b376eed39aa42f38fc4c16213482d868fafe0cf71ecd59431e0 11645 shibboleth-sp_3.4.1+dfsg-2+deb12u1_s390x-buildd.buildinfo Files: 3dc065c3da75ad1cec06b754cc6c3276 391856 debug optional libapache2-mod-shib-dbgsym_3.4.1+dfsg-2+deb12u1_s390x.deb 98a80d4c37a170f05434ea14c7ab5124 62912 httpd optional libapache2-mod-shib_3.4.1+dfsg-2+deb12u1_s390x.deb b35d839b855cbf6001fdcc7a1aa96da0 54396 libdevel optional libshibsp-dev_3.4.1+dfsg-2+deb12u1_s390x.deb f37a00c29b9a44d9f225971af77b3be2 2349960 debug optional libshibsp-plugins-dbgsym_3.4.1+dfsg-2+deb12u1_s390x.deb 05c2acd00c3bf4863bbdf0b63ef551c3 160336 libs optional libshibsp-plugins_3.4.1+dfsg-2+deb12u1_s390x.deb 9ff4c88597fffcac1b03dcf878754de4 20430168 debug optional libshibsp11-dbgsym_3.4.1+dfsg-2+deb12u1_s390x.deb 00ca70d21854c172a7e9b42dafcefb27 864672 libs optional libshibsp11_3.4.1+dfsg-2+deb12u1_s390x.deb 85544946547503f20e1238d1cfe0b00b 420404 debug optional shibboleth-sp-utils-dbgsym_3.4.1+dfsg-2+deb12u1_s390x.deb d2e12cc76ba0352070bbd07c18bc09b5 75468 web optional shibboleth-sp-utils_3.4.1+dfsg-2+deb12u1_s390x.deb 819b64df13b5fee7d9ff910f4f81c5fd 11645 web optional shibboleth-sp_3.4.1+dfsg-2+deb12u1_s390x-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEgh4msZ+e2PZfd5KckaCrxAR3BY0FAmi8qDQACgkQkaCrxAR3 BY29WQ/+M5GG2EWQUGdAdUoxpHQ4JwYib5J4Jux2O9Xgcl7jl9LVbp0Xl7BWQLZO eRrO57eiviLSKgMjZaJNsHuKwKk5aDynL6cmMU4ITFV9prbmJSSo69t8Uu/iKN0F Cz6DxIfSghaDs3lh5K76m7zo+lkq+cjtlFPLWsbXxWf9aK4GqWOMDL80j+RjuoLN m+Bp79jg16bW1A7TV4yW4S+pIxMw3lsbuq4vx17k8fOBZ5OOn/twdDSeswE1SrnB a1EPoEwHZ1AIF+oa/PeHfDjRHH8zoz41XqiIObx7BayOzrGGYPJ934Kjq3/QjyLR JzVd48AUTnzi15+Gsid4gBVk6IUjhuF8/1uZEjKiic4qe9qM09z8K/bN/JIHFQCd Z23F9APu5C3TWrrnitZCkNmLHC4q++w6PB566nBi/4Dn2AhLzOK9fZHQ0dqUqd+2 rGHFFbLkHvwX5Q0RzzpDKcS0ipQVjqyFZxQfs/zBqr1KAkIDlkjr0MG9jIdFsVOH Yg8Kj2C6NPcQAhbghf7vxmUq7JQwBxwpUhtvDwEWWnfarsVBQKvy6CkGUZjWCtnK mQrbq0UFAF1AirmqSxgUXJ1laBFVa3Furuggp4B6q9T2q06ZlxbjO7HbAuXFVhRz 8oB/YT6y8jNLUc7+a/cEwjZspXJUc1rPYzKLLKfY0hogtsV69yU= =7oF7 -----END PGP SIGNATURE-----