-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Sep 2025 11:46:12 +0200 Source: shibboleth-sp Binary: libapache2-mod-shib libapache2-mod-shib-dbgsym libshibsp-dev libshibsp-plugins libshibsp-plugins-dbgsym libshibsp12 libshibsp12-dbgsym shibboleth-sp-utils shibboleth-sp-utils-dbgsym Architecture: ppc64el Version: 3.5.0+dfsg-2+deb13u1 Distribution: trixie-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Ferenc Wágner Description: libapache2-mod-shib - Federated web single sign-on system (Apache module) libshibsp-dev - Federated web single sign-on system (development) libshibsp-plugins - Federated web single sign-on system (plugins) libshibsp12 - Federated web single sign-on system (runtime) shibboleth-sp-utils - Federated web single sign-on system (daemon and utilities) Closes: 1114506 Changes: shibboleth-sp (3.5.0+dfsg-2+deb13u1) trixie-security; urgency=high . * [627cc27] New patch: SSPCPP-1014 - Extend escaping in strings. Fix SQL injection vulnerability in Service Provider ODBC plugin: specially crafted inputs can exfiltrate information stored in the database used by the SP. The vulnerability is moderate to high severity for anyone using the ODBC plugin, and of no impact for others. Thanks to Scott Cantor (Closes: #1114506) Checksums-Sha1: 61602b7babd8804895a974709d76078468b6f3af 400532 libapache2-mod-shib-dbgsym_3.5.0+dfsg-2+deb13u1_ppc64el.deb ade30454a33dead85dfd9c7aaf32e8d86ef7df67 67752 libapache2-mod-shib_3.5.0+dfsg-2+deb13u1_ppc64el.deb 0e480b5adc7a4dcf85802388ae9fa15006603640 54704 libshibsp-dev_3.5.0+dfsg-2+deb13u1_ppc64el.deb 187961a8b4367f2d1dcc640b5ac65fc76c782317 2424452 libshibsp-plugins-dbgsym_3.5.0+dfsg-2+deb13u1_ppc64el.deb 43f80d844a508de371253e037e00d44815c4ede5 176424 libshibsp-plugins_3.5.0+dfsg-2+deb13u1_ppc64el.deb fec658aad6c00425475d609846928a1529e44bd4 21026332 libshibsp12-dbgsym_3.5.0+dfsg-2+deb13u1_ppc64el.deb 6ea821dd0d0cca4df10bdbd6511f1e083af0eeb5 981288 libshibsp12_3.5.0+dfsg-2+deb13u1_ppc64el.deb b9790de4ac24b8a5d59cd25c951b6eb5627a9c3c 464120 shibboleth-sp-utils-dbgsym_3.5.0+dfsg-2+deb13u1_ppc64el.deb 4395a437c9231a0ad5b9e2635e0232c3c29d2010 81020 shibboleth-sp-utils_3.5.0+dfsg-2+deb13u1_ppc64el.deb d8ae4c5a94ac92cbb5ccd0aaa60614dcc654bd0b 12005 shibboleth-sp_3.5.0+dfsg-2+deb13u1_ppc64el-buildd.buildinfo Checksums-Sha256: eebbf765c916de595596dbd253ccaab2c6062de2dbb9f7db5262bcf30c3f6b68 400532 libapache2-mod-shib-dbgsym_3.5.0+dfsg-2+deb13u1_ppc64el.deb 3178a4613ad6cc375751ba8a425295e120b0d66a13c89106746e676a75d0577d 67752 libapache2-mod-shib_3.5.0+dfsg-2+deb13u1_ppc64el.deb e900f3b6f95da04a1b52ba97b926c5a466a9f16a82b844e6630bd3742276e795 54704 libshibsp-dev_3.5.0+dfsg-2+deb13u1_ppc64el.deb f154cbb9c4700621e72e6c995870a43ff3828ec136baf06eb04191b6a3e71e4b 2424452 libshibsp-plugins-dbgsym_3.5.0+dfsg-2+deb13u1_ppc64el.deb a7444d34ab34ea83960fc4f9e87c4f77f0dbda9ce2e6fef2c44798a24d7be688 176424 libshibsp-plugins_3.5.0+dfsg-2+deb13u1_ppc64el.deb cffa21c518eb5fde1ae5532ec39a2e6218fff3c0419c3bb3b3d5c36f0f167602 21026332 libshibsp12-dbgsym_3.5.0+dfsg-2+deb13u1_ppc64el.deb c6118c587bf71a26ef486a25b8f678ccefea12823e52958932b317a623bb0b98 981288 libshibsp12_3.5.0+dfsg-2+deb13u1_ppc64el.deb a46d1913ba01110e6093b1bedaa7db72b0bdc3eafe7ffedcbc963b0b975e6bd1 464120 shibboleth-sp-utils-dbgsym_3.5.0+dfsg-2+deb13u1_ppc64el.deb 423993bb465bb1beaecbc4be9d96c63c10c9c7e3895feaa2a5fa15972e87a347 81020 shibboleth-sp-utils_3.5.0+dfsg-2+deb13u1_ppc64el.deb 1764a38baae0214dbaba34a3195a3a5480fa00d6cf5c89deeaf6a52d2016ac7a 12005 shibboleth-sp_3.5.0+dfsg-2+deb13u1_ppc64el-buildd.buildinfo Files: 8b8dab7930e9b6ff9ca562ce0e0268e4 400532 debug optional libapache2-mod-shib-dbgsym_3.5.0+dfsg-2+deb13u1_ppc64el.deb 24f5d831e31b472860fc53fc73e9a7ce 67752 httpd optional libapache2-mod-shib_3.5.0+dfsg-2+deb13u1_ppc64el.deb d9e14d08454725d40852c41909b3bf43 54704 libdevel optional libshibsp-dev_3.5.0+dfsg-2+deb13u1_ppc64el.deb 773a7e39259baf5183836861f9ee803c 2424452 debug optional libshibsp-plugins-dbgsym_3.5.0+dfsg-2+deb13u1_ppc64el.deb e55f03f3f44ef71a5e378e20d0e35204 176424 libs optional libshibsp-plugins_3.5.0+dfsg-2+deb13u1_ppc64el.deb 0c16c3c4bd3c38fe4c369a685128db54 21026332 debug optional libshibsp12-dbgsym_3.5.0+dfsg-2+deb13u1_ppc64el.deb 009ce0aca46e6cd31adb4e31bb2a7995 981288 libs optional libshibsp12_3.5.0+dfsg-2+deb13u1_ppc64el.deb d1e3c10b76843d613f3a446ec36f4439 464120 debug optional shibboleth-sp-utils-dbgsym_3.5.0+dfsg-2+deb13u1_ppc64el.deb 924712322b268e4fd520e9081499b1e7 81020 web optional shibboleth-sp-utils_3.5.0+dfsg-2+deb13u1_ppc64el.deb 3789cb7f600f3f28d6c59d70c6ee0365 12005 web optional shibboleth-sp_3.5.0+dfsg-2+deb13u1_ppc64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEGHWM+bJZRznwgySGOrVShFbIMGEFAmi8hz8ACgkQOrVShFbI MGFGFA//RBXpqPu4xnCcZK9DKIODQZdE8zoC8BQ6yKz/qeKLOvKayiiVSWWaVWxg DfCac8/XIzspeWO5pLsWdVdTTcgTdjqd/lCh4JlRyhdT223zW/qi11dgJu7XJ5ci v+XG3kLc6kBXIBfpohYO0buHKvDewiKlQW9PeRfgU5POIPjsPnIvaZZfNiCeEUDI gO6ILVcsYmrBEmNDT6FqsEOg/Z69bGizpTEPEJPdztQJOaXuoOkb3lOq0/9u0LHK Yl16y+qFl0ypbVoCpCEF8ugJxAjHCe7ZDeBmaBvV1d3qogUgna8JTo3ME/Pwg2QU VBfKzdMRyuXKtZGs8queU/e3oBaow1wweLFZYoLNZJlvLnub48yK7Nnx+D01vUFE JhQUVcvWUl0qu9HuXcFn18XzB3lLnW4nmN/uVT7UcGlF32VTSsF6elmcvY9Wt3B6 NMDb1p3IDNGpw+GRymsIfZdRbGcBttV107IbMXfOjVGaJnfJuPgKV2hocJV64APR 6yZRFB7bugcH7NOAavtqOkP7uNulPxkH2iOu+I53gjTt93IRpmRhC6lXTHs7x20q f5Ek5w9XUGmpHe3Gk4bYjzpO8DocLTUvodpCeNaHdfR/HB/LpK5NLe4fw5dTyGko k65pa5VNf5wINq1Ci2CTQJYpm12Yf+0cfLjgkTotTS1OfsARfVg= =EmD5 -----END PGP SIGNATURE-----