-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 06 Sep 2025 11:46:12 +0200 Source: shibboleth-sp Binary: libapache2-mod-shib libapache2-mod-shib-dbgsym libshibsp-dev libshibsp-plugins libshibsp-plugins-dbgsym libshibsp12 libshibsp12-dbgsym shibboleth-sp-utils shibboleth-sp-utils-dbgsym Architecture: armhf Version: 3.5.0+dfsg-2+deb13u1 Distribution: trixie-security Urgency: high Maintainer: arm Build Daemon (arm-conova-03) Changed-By: Ferenc Wágner Description: libapache2-mod-shib - Federated web single sign-on system (Apache module) libshibsp-dev - Federated web single sign-on system (development) libshibsp-plugins - Federated web single sign-on system (plugins) libshibsp12 - Federated web single sign-on system (runtime) shibboleth-sp-utils - Federated web single sign-on system (daemon and utilities) Closes: 1114506 Changes: shibboleth-sp (3.5.0+dfsg-2+deb13u1) trixie-security; urgency=high . * [627cc27] New patch: SSPCPP-1014 - Extend escaping in strings. Fix SQL injection vulnerability in Service Provider ODBC plugin: specially crafted inputs can exfiltrate information stored in the database used by the SP. The vulnerability is moderate to high severity for anyone using the ODBC plugin, and of no impact for others. Thanks to Scott Cantor (Closes: #1114506) Checksums-Sha1: cb83e2396114a36c0ee412d61bf9ecc65c33224f 401076 libapache2-mod-shib-dbgsym_3.5.0+dfsg-2+deb13u1_armhf.deb 6a6196caa7de12e1111d60621eb529349fec84e0 60960 libapache2-mod-shib_3.5.0+dfsg-2+deb13u1_armhf.deb 3c13949871a7b0fde95d52bf0e0a13916817e429 54688 libshibsp-dev_3.5.0+dfsg-2+deb13u1_armhf.deb 29cd9053fa3b7ee7aa647d5842626a6a94f87499 2457940 libshibsp-plugins-dbgsym_3.5.0+dfsg-2+deb13u1_armhf.deb 338235881203fe0c4924ca2019b54e8be8ac8af5 159640 libshibsp-plugins_3.5.0+dfsg-2+deb13u1_armhf.deb 471e9ca6847b5fec98b96408c21fbb19c60e5a2c 21355080 libshibsp12-dbgsym_3.5.0+dfsg-2+deb13u1_armhf.deb 8ac8ff51124d509cd60a7fa3efe354b3cfb50c4e 896116 libshibsp12_3.5.0+dfsg-2+deb13u1_armhf.deb 14fac4ac9180a97627156443bd959006dfcba59c 463916 shibboleth-sp-utils-dbgsym_3.5.0+dfsg-2+deb13u1_armhf.deb 91613bfa2eb1011162188474ff2faab64f0116ac 73008 shibboleth-sp-utils_3.5.0+dfsg-2+deb13u1_armhf.deb 876991f0c50cea61243ddd02a5a903da1a4e3e4f 11838 shibboleth-sp_3.5.0+dfsg-2+deb13u1_armhf-buildd.buildinfo Checksums-Sha256: 2553f70129ec929521baae353a57f2c50902c214813aef74945ac1f45fe51ce3 401076 libapache2-mod-shib-dbgsym_3.5.0+dfsg-2+deb13u1_armhf.deb 869bfe2eb61a5e287eb905c4554122ce91be5479cc04d7bdccabfd4244011251 60960 libapache2-mod-shib_3.5.0+dfsg-2+deb13u1_armhf.deb d7da2d6c28d8d0066ec6b5a55b1af177d6d449aa1479b545e15c6f4e27d677cc 54688 libshibsp-dev_3.5.0+dfsg-2+deb13u1_armhf.deb 53cc81451b1ebf46462f7cbf0ef8872612413d7d55d8f18c0efca36502e1be83 2457940 libshibsp-plugins-dbgsym_3.5.0+dfsg-2+deb13u1_armhf.deb c607836b5c2d277ce8fa044135b18d2151402035ece40cb7649d008af9b5ee4f 159640 libshibsp-plugins_3.5.0+dfsg-2+deb13u1_armhf.deb feb920eeca759479c70b514020ad884f066a766e854dbccd88203dd8efa146ca 21355080 libshibsp12-dbgsym_3.5.0+dfsg-2+deb13u1_armhf.deb 787ce1bbc84edaf7fa64d4380bb4b1d337ef1dec199587b22f33fc6da74a2069 896116 libshibsp12_3.5.0+dfsg-2+deb13u1_armhf.deb 32c05f3b786bb0ea870c4d0b04a8d12ecd6bab7515cfc30cf07c2404135782de 463916 shibboleth-sp-utils-dbgsym_3.5.0+dfsg-2+deb13u1_armhf.deb d1f0439925c1e389e7e36deb2bf68ae4082fc7a55a0a52ef35769df0ab87af41 73008 shibboleth-sp-utils_3.5.0+dfsg-2+deb13u1_armhf.deb 7ec68494ddfff16f9559d355011e3971da8e74989d78051acabf0b1ad22b5185 11838 shibboleth-sp_3.5.0+dfsg-2+deb13u1_armhf-buildd.buildinfo Files: 5cc9f2b4e4b5fc823e8e17e5107ca407 401076 debug optional libapache2-mod-shib-dbgsym_3.5.0+dfsg-2+deb13u1_armhf.deb 976c97e4eeb3c41ef625cf2baa82cce5 60960 httpd optional libapache2-mod-shib_3.5.0+dfsg-2+deb13u1_armhf.deb 4d9a1f828e21fd5b9b0ba06c893833e3 54688 libdevel optional libshibsp-dev_3.5.0+dfsg-2+deb13u1_armhf.deb 407c2ed05014a1c50ae2a080ca240293 2457940 debug optional libshibsp-plugins-dbgsym_3.5.0+dfsg-2+deb13u1_armhf.deb 0f3dcfee255cbcae959492afa12facd0 159640 libs optional libshibsp-plugins_3.5.0+dfsg-2+deb13u1_armhf.deb 8de58184bbf1907d6ba135510f9cb2b3 21355080 debug optional libshibsp12-dbgsym_3.5.0+dfsg-2+deb13u1_armhf.deb 1b1d6c8ddeaf28cba94d511bda0a807c 896116 libs optional libshibsp12_3.5.0+dfsg-2+deb13u1_armhf.deb 6c8a2b7e3e3bddad9cec8e6343125f35 463916 debug optional shibboleth-sp-utils-dbgsym_3.5.0+dfsg-2+deb13u1_armhf.deb 672e3832e4bed76db9ca264b4d386af6 73008 web optional shibboleth-sp-utils_3.5.0+dfsg-2+deb13u1_armhf.deb 17a46216e83845c81d1c626fe86d2a0a 11838 web optional shibboleth-sp_3.5.0+dfsg-2+deb13u1_armhf-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEVM4SKBZumztS8zr3lST9Us03ywsFAmi8ihYACgkQlST9Us03 ywuwjhAAwIreKKS5zMu6y7/bt1VwvbGeJJIsDpSQlZjx1LrQW9JMRLKzbunuhjf4 UlZrCEjuh6eEcG0d92hmKN8EZYxXtsc38p/8J/g5d9VSLWsnCqbIYQSg/0dRR9aG DkSnugsrgN8JA+548OUm4h9oRHC0dongucMCOK2oeLMJOm5DZfPvgRlLMveRL5bO 5ZhzabXPvLrFuI2x+ZYimgKmxBvyQKvexyTiV82sLQIEegMJuPeACtXdesBT/Ykq fE2xuaH3aTWAg+PAaZFOsHnbixE+Bf83Rmu3YXKBRLjm6A3NEiusaAIVmsyKXz/u 20t4q8crZd95e4e6BiRyQ1GyoQyu68HS9qZTS62MtYmwENCqHk8vYAQgUY9nSuaX r09aIAaEQeN2+b1Ueb8SI91sscosSjgLD1jbxuFKtNcPAeTQXE/bAHcz0I2SZ7D9 RpOS76yJU4VwkuTem2/i3zXmsuAjrlSgyoo95oc//LnXOTlUvB5XS9/Rz7PVnTN+ 4hOy8onDPj+ObVx8XS9e8h80dB+NDekZnRph9DN7DwCrzPmxVnt6tf4v7ra9BC4d 1rSRHqCpFmdepzRYAyRYlmHSfVpDXkdJq+0djIpORtKg/H58cTAX36UcrIsdfllM kAfitpXdmh0zGBChfWkuWiSWpYq7NEC3RCUX1qWzeXC1svDnmBw= =zufs -----END PGP SIGNATURE-----