-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Sep 2025 11:46:12 +0200 Source: shibboleth-sp Binary: libapache2-mod-shib libapache2-mod-shib-dbgsym libshibsp-dev libshibsp-plugins libshibsp-plugins-dbgsym libshibsp12 libshibsp12-dbgsym shibboleth-sp-utils shibboleth-sp-utils-dbgsym Architecture: arm64 Version: 3.5.0+dfsg-2+deb13u1 Distribution: trixie-security Urgency: high Maintainer: arm Build Daemon (arm-conova-04) Changed-By: Ferenc Wágner Description: libapache2-mod-shib - Federated web single sign-on system (Apache module) libshibsp-dev - Federated web single sign-on system (development) libshibsp-plugins - Federated web single sign-on system (plugins) libshibsp12 - Federated web single sign-on system (runtime) shibboleth-sp-utils - Federated web single sign-on system (daemon and utilities) Closes: 1114506 Changes: shibboleth-sp (3.5.0+dfsg-2+deb13u1) trixie-security; urgency=high . * [627cc27] New patch: SSPCPP-1014 - Extend escaping in strings. Fix SQL injection vulnerability in Service Provider ODBC plugin: specially crafted inputs can exfiltrate information stored in the database used by the SP. The vulnerability is moderate to high severity for anyone using the ODBC plugin, and of no impact for others. Thanks to Scott Cantor (Closes: #1114506) Checksums-Sha1: 3ebc0eb327b3e75af93c8332ceebc7293d19b61e 398308 libapache2-mod-shib-dbgsym_3.5.0+dfsg-2+deb13u1_arm64.deb b2731b3c491a2153f4281090cd3b8499e20e8421 62988 libapache2-mod-shib_3.5.0+dfsg-2+deb13u1_arm64.deb 63838964c8b2d4feabd1dc3d2f2ae46e153abeba 54700 libshibsp-dev_3.5.0+dfsg-2+deb13u1_arm64.deb d49662e45bf8e52ed9b821ac1660dbfbc0c7bbf7 2419172 libshibsp-plugins-dbgsym_3.5.0+dfsg-2+deb13u1_arm64.deb c9b567a289c480105641b2003a16d85a5abd0a08 162996 libshibsp-plugins_3.5.0+dfsg-2+deb13u1_arm64.deb 80226e9b853f52691acca8c08925ec00ff195a9f 21124944 libshibsp12-dbgsym_3.5.0+dfsg-2+deb13u1_arm64.deb c8a6d4a0c6e2295a0e6264cbd24213cbe924084b 902928 libshibsp12_3.5.0+dfsg-2+deb13u1_arm64.deb 661c94022f91ecb78db32b0a3a3972e768c2f6cf 464236 shibboleth-sp-utils-dbgsym_3.5.0+dfsg-2+deb13u1_arm64.deb b6385aaedb58b92372190ea3a650ceb815e4e2e4 76924 shibboleth-sp-utils_3.5.0+dfsg-2+deb13u1_arm64.deb a95a8e6d0ce9143fbbb24feed4131fce07fea2cf 11959 shibboleth-sp_3.5.0+dfsg-2+deb13u1_arm64-buildd.buildinfo Checksums-Sha256: 7210f4b5ea894cae777e0bb457428846164bcbdfa88dacf3057b578610273374 398308 libapache2-mod-shib-dbgsym_3.5.0+dfsg-2+deb13u1_arm64.deb 3c514653fca77e2429a3f4f366b6c7229b948a157ee483afc42450f6617fd8f6 62988 libapache2-mod-shib_3.5.0+dfsg-2+deb13u1_arm64.deb 7e353da8abb4884bf635b3b399a6ea2b2c0797f548d0e9d3e38871b7469f2646 54700 libshibsp-dev_3.5.0+dfsg-2+deb13u1_arm64.deb c03850e845cb8929d0915bfd4e4cfec6d62c077cf8170d012f9306f65ae702d6 2419172 libshibsp-plugins-dbgsym_3.5.0+dfsg-2+deb13u1_arm64.deb 29f7f0ce1230323b82b247028ac709e3321ea5e25fac23a843ebd7c5fc812c6d 162996 libshibsp-plugins_3.5.0+dfsg-2+deb13u1_arm64.deb 2146e220a2a553b275cad537f19690b8e0768355d2cc00b05fd462fc51adae32 21124944 libshibsp12-dbgsym_3.5.0+dfsg-2+deb13u1_arm64.deb 2622ef90ec5c162be95e6eeff344885fa3a17aa2e6dd80fd6e1f9e68bc79831a 902928 libshibsp12_3.5.0+dfsg-2+deb13u1_arm64.deb fc606fcb82c3a89371164b6dfee3b1d1f48814978c9ff2a7bb8a626cc8e74777 464236 shibboleth-sp-utils-dbgsym_3.5.0+dfsg-2+deb13u1_arm64.deb 75eb11c4b9643b20a48cfc0374468864a8d92b65d163cbbe911aba5622d564b5 76924 shibboleth-sp-utils_3.5.0+dfsg-2+deb13u1_arm64.deb e0617d996095342237b2e31f9989d205406d87e3dfaa4741d0fbf70a5f4d14b2 11959 shibboleth-sp_3.5.0+dfsg-2+deb13u1_arm64-buildd.buildinfo Files: bc1249102b899296704317dc38ae4253 398308 debug optional libapache2-mod-shib-dbgsym_3.5.0+dfsg-2+deb13u1_arm64.deb c0e42ad46891575f936bff105d84dd97 62988 httpd optional libapache2-mod-shib_3.5.0+dfsg-2+deb13u1_arm64.deb 014c176891f9502aec8cb63f8e622b75 54700 libdevel optional libshibsp-dev_3.5.0+dfsg-2+deb13u1_arm64.deb c3809ad9587d8a62750848ceae14027e 2419172 debug optional libshibsp-plugins-dbgsym_3.5.0+dfsg-2+deb13u1_arm64.deb aebe0102d0fcafb951539e54f9f44403 162996 libs optional libshibsp-plugins_3.5.0+dfsg-2+deb13u1_arm64.deb 648b28fa37c3de57f2000cd6c6234dbb 21124944 debug optional libshibsp12-dbgsym_3.5.0+dfsg-2+deb13u1_arm64.deb 5ae78e360db2d99b128e1f7bff38d9d0 902928 libs optional libshibsp12_3.5.0+dfsg-2+deb13u1_arm64.deb 7312c2cee70a321d1e8ed0051b544884 464236 debug optional shibboleth-sp-utils-dbgsym_3.5.0+dfsg-2+deb13u1_arm64.deb 194d72048c67cd5e3b58fadf88499e97 76924 web optional shibboleth-sp-utils_3.5.0+dfsg-2+deb13u1_arm64.deb 89328147ad3edb012aaed4ecf665e59e 11959 web optional shibboleth-sp_3.5.0+dfsg-2+deb13u1_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEvEwFZ4bqkVI+Rh6t+N4VxR6LZYEFAmi8iZMACgkQ+N4VxR6L ZYEHuhAAlFbZktHhWJHwtHAdPjCEevsQvVS8S92N86l2Te0LoSQ/9AHnUfh7lkjj wewm5dOWASUloaHDPBR1vD/9gyGaaLEBZz+YNeHrzMkn/eOfgmpsnV5hFesJb/IN hlJioPFGuA5f2zNgzjsEGC8EBmKOLwmtXdfxiO8Kry9gbrxM3VYabssRdT4HGGRh 3VrhfKigyGwRTUdfDQZmsyWXhA1xUebfjxhEwvRcXZ4zkuf6mtOp/UasN02mR71Z nufNBWSHYIJK2UFWXGq2BIFPlmYTc01fNf7321LEB7/NUKDQZR0ub75Vw1PtdoFW /U9cS6WB91yzfVO6/Re69DVACw89DbWJcv4ycNVMwPgMn08CWfO93Gu7V9p94O75 rjhMOKwDR6fk1JHWhGxpCi+Dgloj8q0lY+6r6sFjEOuI7hTMCsaSNZhfsYekIXPY Ip0/vrUE5DuTyobRdaikFQlNJaaYGbLQZk67R4k4xL7PeYHsSv/VFVeliV0I8S7m /o9fZG0LbH4MCFm7GGAEztzpoNof/YVVlfEK9Ybmi6FbtehRFx4Y4joSFKPG7Ga2 n5ExJ9zvckh+7wTh0xLsUhCYXybD5msApflwOZH9YVbYu0qKsYPT3Nr6LJeM01Ny SzZEqzm1DMKbvkacHHoEy+jIfGhtRmok4/24y/7hr4BolTLWkqU= =i0I4 -----END PGP SIGNATURE-----