-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 07 Nov 2025 21:10:39 +0100 Source: lasso Binary: liblasso-perl liblasso-perl-dbgsym liblasso3-dev liblasso3t64 liblasso3t64-dbgsym python3-lasso python3-lasso-dbgsym Architecture: s390x Version: 2.8.2-9+deb13u1 Distribution: trixie-security Urgency: high Maintainer: s390x Build Daemon (zani) Changed-By: Salvatore Bonaccorso Description: liblasso-perl - Library for Liberty Alliance and SAML protocols - Perl bindings liblasso3-dev - Library for Liberty Alliance and SAML protocols - development kit liblasso3t64 - Library for Liberty Alliance and SAML protocols - runtime library python3-lasso - Library for Liberty Alliance and SAML protocols - Python bindings Changes: lasso (2.8.2-9+deb13u1) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * tests: test that inserted comment do not change node value and still validate signature * xml: prevent assignment of attribute value inside any attribute (CVE-2025-47151) * misc: check xmlSecGetNodeNsHref for possible NULL result (CVE-2025-46404) * xml: do not terminate on an unknown XML node type (CVE-2025-46705) Checksums-Sha1: 379016d42042f0ed1745f710e992b1f4f82499bf 10910 lasso_2.8.2-9+deb13u1_s390x-buildd.buildinfo 5b0ec10558e246c36940fa6106d138edcc604002 172472 liblasso-perl-dbgsym_2.8.2-9+deb13u1_s390x.deb 8e6c56ea15daf0b207d35581a44e30b92eea671c 764516 liblasso-perl_2.8.2-9+deb13u1_s390x.deb e910a8e82a5657f1f5fe434cbfd7957c614c4ae2 854348 liblasso3-dev_2.8.2-9+deb13u1_s390x.deb 667d2ed807183d90dc033738231054fcb466ebc4 816920 liblasso3t64-dbgsym_2.8.2-9+deb13u1_s390x.deb 4407a7b1256b08dbd165dce7035c81459d76280c 779480 liblasso3t64_2.8.2-9+deb13u1_s390x.deb 584666c9fd75c6a806342d3e4ae3853bb32aaf60 358184 python3-lasso-dbgsym_2.8.2-9+deb13u1_s390x.deb b8b803639b69b92fcb6b4b422c1430088d11d138 738624 python3-lasso_2.8.2-9+deb13u1_s390x.deb Checksums-Sha256: 42a9c0d244f54cefada43cace94af0a961f760c181b0fc09272cfa9881219988 10910 lasso_2.8.2-9+deb13u1_s390x-buildd.buildinfo 8a8ff3e1ec84d2ea9dfe032c2af0f81d1abe8244822bab216fceea188d226266 172472 liblasso-perl-dbgsym_2.8.2-9+deb13u1_s390x.deb 5f0a82fdacd98238f1ca5e55865c4c8e673bb2a7ca441f9820abd6e62b6ee52d 764516 liblasso-perl_2.8.2-9+deb13u1_s390x.deb e43dc0d98d5e967084a1c4b2ac4b3824a2829c7ef08d030bcca5f26fecf378d2 854348 liblasso3-dev_2.8.2-9+deb13u1_s390x.deb 8832ac892ad52e33202df646aecb4ede64417b433d662ce6522a78c3c84bd4ec 816920 liblasso3t64-dbgsym_2.8.2-9+deb13u1_s390x.deb 5f5c19e56370b4d5da61649b433f08a28119568c2ca3d4a1dac821c5abf6a2cd 779480 liblasso3t64_2.8.2-9+deb13u1_s390x.deb 6503b682e60539e410d8cab6d1573798e45c36e8060a9c09e8874145a3be3a0e 358184 python3-lasso-dbgsym_2.8.2-9+deb13u1_s390x.deb 95fcd189d9217917bee187cb177972b98a6e8a796fae6f03d2fb2a8ea64c4dc3 738624 python3-lasso_2.8.2-9+deb13u1_s390x.deb Files: 7a75bf14e8d1a790f15bad841db669c4 10910 libs optional lasso_2.8.2-9+deb13u1_s390x-buildd.buildinfo f4f1decf38c23de8d034c316d2c2472d 172472 debug optional liblasso-perl-dbgsym_2.8.2-9+deb13u1_s390x.deb ffbdd6f5c7ed9f09c9d879057457fe9c 764516 perl optional liblasso-perl_2.8.2-9+deb13u1_s390x.deb 3c35e053b789ef194270a74ff2840031 854348 libdevel optional liblasso3-dev_2.8.2-9+deb13u1_s390x.deb 13848453b4c8aca50bcf8b4367cd5de6 816920 debug optional liblasso3t64-dbgsym_2.8.2-9+deb13u1_s390x.deb e95b5a595be899915865fb66d5003260 779480 libs optional liblasso3t64_2.8.2-9+deb13u1_s390x.deb e83a8276bcbd57f3f8a13eb467cc2380 358184 debug optional python3-lasso-dbgsym_2.8.2-9+deb13u1_s390x.deb c99e2bf4adb9c409ac7ef2341af4687e 738624 python optional python3-lasso_2.8.2-9+deb13u1_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEgh4msZ+e2PZfd5KckaCrxAR3BY0FAmkSTyAACgkQkaCrxAR3 BY2tMw/+I24ZLZEH2iTmMOBVWETyk9swfA8ptPy57uvKou8pYWC1RQ+3e44Jzshp PR98zW4TGovEMH45Liu7kzduIbm5SV6LSEF3hU5qfc9ShL+JV0E6Xpq6YmKyHDxj d0vIsGOAK0YqKKMwCswMVspyWANjgLXgqhZgDQCiwsCYHlg+65Ln0brX6nJs/Trt zffYycNJvLRCmqIhBh8BbH3kC6ZXlaGT16Rw5KGxRgbQIxBzpFVKB3gPrtiyZwxT cUGZI5AJOK9tNNbpwv2YmP5vOB+MjLjzrp3jA1M5+GLuSh2WBE8k+2JnhAqWkEiU RQWrO6/07/IML0hgUZfvSc75tSG3zeZs/PVOKfUuf3g3RVx8hIAMV6UfFE5HuTKZ WeKT9eINUI6tEWw0OlsgAp4xxjf472B5gLH8OeP3TZIAQrgFfXJLhBymTdITFfgC nfRZ/GN8klPq1FkOAMFHnsN1dtE7iAcgCyK/7yaGWSl6uapOCrtBwJhYwSkqkM5r pklIK0dxCAbmX60zljEust3bQ+vN7yfnfxXKG0bPnk/H6WB6Vxo6V+Ft90A68VBa 38dDOz/nBKxxr4Ff1Cg+hmaC1RYehRjtOEQaN8yQz8Jyvqdapp/bDPrMdTOHmWeL M61LMUr9pr4zOxMvNVGVfvg0l+UKOwNvAcVS8wxuPvCVXMGiCIg= =w3eP -----END PGP SIGNATURE-----