-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 07 Nov 2025 21:10:39 +0100 Source: lasso Binary: liblasso-perl liblasso-perl-dbgsym liblasso3-dev liblasso3t64 liblasso3t64-dbgsym python3-lasso python3-lasso-dbgsym Architecture: armel Version: 2.8.2-9+deb13u1 Distribution: trixie-security Urgency: high Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Salvatore Bonaccorso Description: liblasso-perl - Library for Liberty Alliance and SAML protocols - Perl bindings liblasso3-dev - Library for Liberty Alliance and SAML protocols - development kit liblasso3t64 - Library for Liberty Alliance and SAML protocols - runtime library python3-lasso - Library for Liberty Alliance and SAML protocols - Python bindings Changes: lasso (2.8.2-9+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * tests: test that inserted comment do not change node value and still validate signature * xml: prevent assignment of attribute value inside any attribute (CVE-2025-47151) * misc: check xmlSecGetNodeNsHref for possible NULL result (CVE-2025-46404) * xml: do not terminate on an unknown XML node type (CVE-2025-46705) Checksums-Sha1: 1ceaeed8454a41957c012c8bd61648c7f6515e4a 10900 lasso_2.8.2-9+deb13u1_armel-buildd.buildinfo 078081b2150cb66ad2ebf5c30cba377d7aba3b6b 177404 liblasso-perl-dbgsym_2.8.2-9+deb13u1_armel.deb 1d47f5291bd8c25da29770d95adcf2ad1d895408 762448 liblasso-perl_2.8.2-9+deb13u1_armel.deb 23d0851ae0ff558e2cf5d2f21a478a5a031409ab 845460 liblasso3-dev_2.8.2-9+deb13u1_armel.deb de2a889a81633fb3508983ec73a5990f775cc3aa 797308 liblasso3t64-dbgsym_2.8.2-9+deb13u1_armel.deb f017f650fb9fb7497c750f3486c9c1b28f0a2d17 764760 liblasso3t64_2.8.2-9+deb13u1_armel.deb 58b0882aeec92ab1bb106c39f3ca2b05643700a0 351160 python3-lasso-dbgsym_2.8.2-9+deb13u1_armel.deb 904e540303eb421387729b8f1bd6a323791c6519 728892 python3-lasso_2.8.2-9+deb13u1_armel.deb Checksums-Sha256: e29480e6cf2c45745b6a552c4d7f1e34561a17370d17003e8e54dd25ee773f59 10900 lasso_2.8.2-9+deb13u1_armel-buildd.buildinfo f0a49d2205f4cfe7893de90f896758752d126d4cb5121093390af819539dfc50 177404 liblasso-perl-dbgsym_2.8.2-9+deb13u1_armel.deb d6b83968129e07c373c60e230e8756ecfde304946a6310c3b056afd5aeb95791 762448 liblasso-perl_2.8.2-9+deb13u1_armel.deb e9de38c498b1d3203507e6e90427ae9dbfb481bc42159db2e26d0b3bd8e45763 845460 liblasso3-dev_2.8.2-9+deb13u1_armel.deb ed71092478a41f1facb2b7d8211ab08467db2d3dfb97aa39d7b41c8af28f734c 797308 liblasso3t64-dbgsym_2.8.2-9+deb13u1_armel.deb 5934bc6d909b3ebe68b29292a9b4a3e36ae55cea106d4934fa0d763b531aa366 764760 liblasso3t64_2.8.2-9+deb13u1_armel.deb 1fa39d39efa98c095295e2513e8b0d46abb87b6c4a426fa689ff55ed6b734fd9 351160 python3-lasso-dbgsym_2.8.2-9+deb13u1_armel.deb 33f08a9f222618bd9de890c42d85f04febd295171c58e1b6ad6d39a60682af12 728892 python3-lasso_2.8.2-9+deb13u1_armel.deb Files: e616fb2f9ea301fe7d724267f544b0fd 10900 libs optional lasso_2.8.2-9+deb13u1_armel-buildd.buildinfo 5f841207f3f577cff5ef6c95c72f60e5 177404 debug optional liblasso-perl-dbgsym_2.8.2-9+deb13u1_armel.deb db28f79670678036c22b07d50122287e 762448 perl optional liblasso-perl_2.8.2-9+deb13u1_armel.deb feede46f540088eb4938f56a67c8185b 845460 libdevel optional liblasso3-dev_2.8.2-9+deb13u1_armel.deb 596b4b7821d03b9454ce82cb4190e3bc 797308 debug optional liblasso3t64-dbgsym_2.8.2-9+deb13u1_armel.deb e85d4bc8212a1a235ece6ffa99fad458 764760 libs optional liblasso3t64_2.8.2-9+deb13u1_armel.deb f0d71467261c50cd04c3ab5470a097d2 351160 debug optional python3-lasso-dbgsym_2.8.2-9+deb13u1_armel.deb e5be9f48963c6ed1128beb57d447bd4b 728892 python optional python3-lasso_2.8.2-9+deb13u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEWHj9K9pO9l4btbD1OQKMdMnEH5MFAmkST38ACgkQOQKMdMnE H5MufBAAvVPWaL6CNwHNBygNh2aQxn4VuwgIeJuS8NHflLrHp1m5zZG62HLYAJTD rKgDqmwZBiCWDnu5nzdwMOtGoyYGjmoH17K5MxQOv3iqBtcU6YW9KPQdbLCLr3l5 ISak3PdOVYx65KF1Y28LT9YEUSb3QCspIdInS85rYHrpQ5Ws1fA9/k7utGbuCH64 1YRMmPJ87x1rO7lXiyjQe6anDv1mvvPi6sFuaCuvRFvT7LRouv/l1g0Wr217plf1 pDua0/Xfu+DdtEypruewxRZlA4OeuBJacvguyNRDUL8zY2E20Ja+UB2QDhClJfcL hjSg8X+lqaE9ECQ1AfdMTvJfZlKqypccY19U6dfIFLt18NAhtwtXb3sqALxDIIQH LElgwrDN4GAiyLMQ0PBfH0OEapXJxhKvMNR8pgRt3Vhx4W1r6vluKIYMxZwXeYpF KoiI1VF+LB2e7mP/LZrb7ige1glxOTfXuUqcAgC86K009OuF+hIfX+V7roQ02ycE eD6HDep80GaATdR4UGc3OE62Y5JpwiA/Rg92Vh4Yjym1cJAkekXbslwGopDBdTdv oQLMYcrzV94cWI+fZVSWRiCttWzcIwT91wEu21wSZxD5tZ82kAHqXoeS0549RuLe ZWMozEzXuInzXQKsN7S64azu17tZ2pk06yrF/tKY51u4taqUvN4= =NCkO -----END PGP SIGNATURE-----