-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Sep 2025 11:46:12 +0200 Source: shibboleth-sp Binary: libapache2-mod-shib libapache2-mod-shib-dbgsym libshibsp-dev libshibsp-plugins libshibsp-plugins-dbgsym libshibsp12 libshibsp12-dbgsym shibboleth-sp-utils shibboleth-sp-utils-dbgsym Architecture: armel Version: 3.5.0+dfsg-2+deb13u1 Distribution: trixie-security Urgency: high Maintainer: arm Build Daemon (arm-conova-02) Changed-By: Ferenc Wágner Description: libapache2-mod-shib - Federated web single sign-on system (Apache module) libshibsp-dev - Federated web single sign-on system (development) libshibsp-plugins - Federated web single sign-on system (plugins) libshibsp12 - Federated web single sign-on system (runtime) shibboleth-sp-utils - Federated web single sign-on system (daemon and utilities) Closes: 1114506 Changes: shibboleth-sp (3.5.0+dfsg-2+deb13u1) trixie-security; urgency=high . * [627cc27] New patch: SSPCPP-1014 - Extend escaping in strings. Fix SQL injection vulnerability in Service Provider ODBC plugin: specially crafted inputs can exfiltrate information stored in the database used by the SP. The vulnerability is moderate to high severity for anyone using the ODBC plugin, and of no impact for others. Thanks to Scott Cantor (Closes: #1114506) Checksums-Sha1: 6d229cdd5753472ff39721679e266c898e709a65 397920 libapache2-mod-shib-dbgsym_3.5.0+dfsg-2+deb13u1_armel.deb c9de4b495eb8c6a7603a97adf2586ecd55c0d2bd 59488 libapache2-mod-shib_3.5.0+dfsg-2+deb13u1_armel.deb 9b63df93742f14c7ca735b8ef33c706a0e2acdd0 54688 libshibsp-dev_3.5.0+dfsg-2+deb13u1_armel.deb f0b6672631ae23c5d6bf738b3c5ba36ba940937e 2450700 libshibsp-plugins-dbgsym_3.5.0+dfsg-2+deb13u1_armel.deb 5a86e4c8301658885ed09363796d4e093152358e 154848 libshibsp-plugins_3.5.0+dfsg-2+deb13u1_armel.deb 4b4f6d6756d9c5a40cd3ee30b88fbe59121699b8 21261512 libshibsp12-dbgsym_3.5.0+dfsg-2+deb13u1_armel.deb 6dec14173b3f38d6a9ea881ddc87b6afb61da5c8 863088 libshibsp12_3.5.0+dfsg-2+deb13u1_armel.deb 70912179d4dfd880d1780899d9fb1fd389cf4311 460308 shibboleth-sp-utils-dbgsym_3.5.0+dfsg-2+deb13u1_armel.deb 272e174326f6248d49764a50d6f9a20d5cffea58 72192 shibboleth-sp-utils_3.5.0+dfsg-2+deb13u1_armel.deb e0924afd06f83d9de4b535ef79212e06c0e295ff 11824 shibboleth-sp_3.5.0+dfsg-2+deb13u1_armel-buildd.buildinfo Checksums-Sha256: 624b55e2392ea3d30f7824236fa855d71fbb4b59fa83b3b9d5613c04f486efbd 397920 libapache2-mod-shib-dbgsym_3.5.0+dfsg-2+deb13u1_armel.deb cabe20d8de02b1cec98b3583e637502365b6c76cd7359d3da8bf4381764ca366 59488 libapache2-mod-shib_3.5.0+dfsg-2+deb13u1_armel.deb 5315766be1295b3d5170e20bbbd7710b1ec270cab748239b128908efc455a703 54688 libshibsp-dev_3.5.0+dfsg-2+deb13u1_armel.deb 9a8e2a697c64ee337bec4ebe13ab7c8b37f7d8e104a5ddafe891b5b83f6e69f3 2450700 libshibsp-plugins-dbgsym_3.5.0+dfsg-2+deb13u1_armel.deb f95481794dcc0a4b98b23544ec8d04ece647164540e26e82ad8b2ab0418dd56b 154848 libshibsp-plugins_3.5.0+dfsg-2+deb13u1_armel.deb 0fbd3eda7555ae84c8325c49ff09b24915f813623bfa1c60849c77b37006d004 21261512 libshibsp12-dbgsym_3.5.0+dfsg-2+deb13u1_armel.deb 4735d4651e612ca3eaaf8188886f7d7f43f2544b3323cd82692884dc75536c79 863088 libshibsp12_3.5.0+dfsg-2+deb13u1_armel.deb 0e184ee5fae1e7e2c6dd5f1ab161df22148211b0a21f9970856f53f2b95764ae 460308 shibboleth-sp-utils-dbgsym_3.5.0+dfsg-2+deb13u1_armel.deb daf059d0b53344aefae7c41cc400e3ce88d9db50938d14bc2e4368cfa339635f 72192 shibboleth-sp-utils_3.5.0+dfsg-2+deb13u1_armel.deb 385a7ea1b47d1bee3af5a1e7c9f309b12f0f1a7f70830d82214d2585e0ddefd0 11824 shibboleth-sp_3.5.0+dfsg-2+deb13u1_armel-buildd.buildinfo Files: a50dbea17e8a01ec3a2c772b6d9e319c 397920 debug optional libapache2-mod-shib-dbgsym_3.5.0+dfsg-2+deb13u1_armel.deb f05ed06840d13dd5b67cf78488b6828a 59488 httpd optional libapache2-mod-shib_3.5.0+dfsg-2+deb13u1_armel.deb 6fd8e6bf98ecb38aae66745193f6f0dc 54688 libdevel optional libshibsp-dev_3.5.0+dfsg-2+deb13u1_armel.deb 9e6a455483464927a0a2479d62ca4c72 2450700 debug optional libshibsp-plugins-dbgsym_3.5.0+dfsg-2+deb13u1_armel.deb 8971235d1f41470209f12349b266a8a9 154848 libs optional libshibsp-plugins_3.5.0+dfsg-2+deb13u1_armel.deb a39363255d7f36b9550b8c4912d561e3 21261512 debug optional libshibsp12-dbgsym_3.5.0+dfsg-2+deb13u1_armel.deb b1e204cbba7266192e0309a522318ae0 863088 libs optional libshibsp12_3.5.0+dfsg-2+deb13u1_armel.deb c3e8aa5fd5090a839ec946f4a15be45f 460308 debug optional shibboleth-sp-utils-dbgsym_3.5.0+dfsg-2+deb13u1_armel.deb 1b6129f146f3ad2a3a9f8b22c27fdd4a 72192 web optional shibboleth-sp-utils_3.5.0+dfsg-2+deb13u1_armel.deb 4a818804a14f699610d7f3ccd3d461cd 11824 web optional shibboleth-sp_3.5.0+dfsg-2+deb13u1_armel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEWHj9K9pO9l4btbD1OQKMdMnEH5MFAmi8iX8ACgkQOQKMdMnE H5MRiA//SMVjZlUcY+8YBt00whMhsJdrLApU04/sbtr/9hyd9eRfJ0uK2zxrQdcz mibGpxqOYhH35cB8yq2APEur7ihsaXvl3AZoZcaFXTEJAVD/vZ7f62oRSC+OqmxC GOxDQplznd5LuuiTKgDl1cV2fTDOJwS10mMtVDDdcFyMBszsc11sQnEsbdr8POdw vDbIwU/c6fir34QtwZoZasNIYItksjWCcR395vbnKEjMYjd1hNvskFyIElnVD44a xdP9qRejsE9dovIvtvd7G7F9QW/DBj+qFY4uNEXtwz5yMf53JWQDYpXLJUb5NGCY XJPr+/W8MQ03MI05pXJrKfVeNIOQPSMl3WHzbSUZzX9vxiNeyngp1t4+1DiatuMl dsN9NT198DJrOn3UMzYv04bjp7Mo32MbvUEkt3DBWW9ZWlMRma26NP9RXlR90/Z/ 4BDTi/I8HwjIH4OIRNknfQr7MzUZHHkMGF3v5mnmnMiNL+acc6ijyhcj31crq+Ig ESuhtwplXiVjFVHvy3+xfqv23ssKfk4j3veNIpm/Imf3n1QqPTUcAVcI6pNXHGIu 4voBsFZex/6PaCW+xdywf2XAcyymv0Dy7m6IrQfsRC2ZTRKOVbYw6AcPCJj+Wt1R y0jerlrxWhbiUGHJardmWVATm1KYiEGOZ36RwBIXza37fDvNVtQ= =QqDM -----END PGP SIGNATURE-----