-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 07 Nov 2025 21:51:12 +0100 Source: lasso Binary: liblasso-perl liblasso-perl-dbgsym liblasso3 liblasso3-dbgsym liblasso3-dev python3-lasso python3-lasso-dbgsym Architecture: armel Version: 2.8.1-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-06) Changed-By: Salvatore Bonaccorso Description: liblasso-perl - Library for Liberty Alliance and SAML protocols - Perl bindings liblasso3 - Library for Liberty Alliance and SAML protocols - runtime library liblasso3-dev - Library for Liberty Alliance and SAML protocols - development kit python3-lasso - Library for Liberty Alliance and SAML protocols - Python bindings Changes: lasso (2.8.1-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * tests: test that inserted comment do not change node value and still validate signature * xml: prevent assignment of attribute value inside any attribute (CVE-2025-47151) * misc: check xmlSecGetNodeNsHref for possible NULL result (CVE-2025-46404) * xml: do not terminate on an unknown XML node type (CVE-2025-46705) Checksums-Sha1: 28ecca7328629b7196f2497f15adbd0b166f9e23 10933 lasso_2.8.1-1+deb12u1_armel-buildd.buildinfo 82860d74452fa0ec0bddb18759eec13ef5394645 175276 liblasso-perl-dbgsym_2.8.1-1+deb12u1_armel.deb d3f8e20a11ce3cd664b7841b4cf53286a4985924 768356 liblasso-perl_2.8.1-1+deb12u1_armel.deb 54023fbc88eae49d49ab2361d5073f66858798bd 768804 liblasso3-dbgsym_2.8.1-1+deb12u1_armel.deb 990dd1fcaf8deb6edeec4c1ee643c8e04a62f8f1 849728 liblasso3-dev_2.8.1-1+deb12u1_armel.deb be33e3df88c0c0729adb7b182f22e37e66102f45 768796 liblasso3_2.8.1-1+deb12u1_armel.deb 4e2d227833ac4a82fc1d6ff35b70c2927580b156 340572 python3-lasso-dbgsym_2.8.1-1+deb12u1_armel.deb ceac16cce503e50de4251c5b2d33d553f3233ff2 728084 python3-lasso_2.8.1-1+deb12u1_armel.deb Checksums-Sha256: e3d1d2bb8355cecd1f5a8b9d532dd535a98b0ad1256008481553d551930eebf2 10933 lasso_2.8.1-1+deb12u1_armel-buildd.buildinfo 0a19d0d87b4b4e4040a9b33a6cfc1cf3e3dd71abccbbc453c256068555fd0408 175276 liblasso-perl-dbgsym_2.8.1-1+deb12u1_armel.deb 0473d15b353795a24ea836c8dc43b64e08bcdb31057ba4ef92b9b3bd5f551230 768356 liblasso-perl_2.8.1-1+deb12u1_armel.deb f862790df3f4e2501a5a884193de55e7f029a121f0d07d6bc3acc995c8ce8625 768804 liblasso3-dbgsym_2.8.1-1+deb12u1_armel.deb 151a0b90ab27a3b156d4f250abbcfbcbf2d068410d4c2b8b3676bd86fc7a8e09 849728 liblasso3-dev_2.8.1-1+deb12u1_armel.deb 0bc5b312f6cdaa5db015f32ff4ebbfa22c5a30f737af391e1c6f4d586b10289d 768796 liblasso3_2.8.1-1+deb12u1_armel.deb c864a43ce2cf9ac6f78565db31d6d08a5144a576624a8758aa58f82305055b91 340572 python3-lasso-dbgsym_2.8.1-1+deb12u1_armel.deb ceb5348123e5c317b75dd956239ec68b2b497836a74e665cbfe40900c149a3c3 728084 python3-lasso_2.8.1-1+deb12u1_armel.deb Files: fff740cb93ac8d64cdaa26bda527f020 10933 libs optional lasso_2.8.1-1+deb12u1_armel-buildd.buildinfo 13c4d24167e782beacbaedeaa9015785 175276 debug optional liblasso-perl-dbgsym_2.8.1-1+deb12u1_armel.deb e56db093cb472af33b3cca343cec6477 768356 perl optional liblasso-perl_2.8.1-1+deb12u1_armel.deb a1dccb57a75f34a8b4ccbcc7a3fba89e 768804 debug optional liblasso3-dbgsym_2.8.1-1+deb12u1_armel.deb 39faa7ce86e185265bed24d216eb3bcd 849728 libdevel optional liblasso3-dev_2.8.1-1+deb12u1_armel.deb 0b6c3ec4b7ff343afd22cb9270d7f1ab 768796 libs optional liblasso3_2.8.1-1+deb12u1_armel.deb 85647f7e3468de4df577e9b50a62e328 340572 debug optional python3-lasso-dbgsym_2.8.1-1+deb12u1_armel.deb f35dd7d2fcf8b843ba73ec9ae0e3612a 728084 python optional python3-lasso_2.8.1-1+deb12u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEpxWVfktWxVoKRwGgJ7tNDw2WyRsFAmkSTzYACgkQJ7tNDw2W yRsQ7Q//W9jv3AJ3/GR1+CyaL0+dzurin+kkgpEYlvdO3y1FRxhPBcUP0vtEiO9a NfXLhsAotKxYrghV1GWX1O5r+B7A3+D1v0mXw8cKmjtimTvGjp8z48OVRLvlU5gy exVjxLIKduyv9tJGaKtz1a6WI/m+13xwbEPwDGmwYjnDxnRNkfYBRt5u5pHJFO5R Nw7dUxqqag59vT5I10B2oAIvt/7FaS40NqaOVnqKB7dO+8hzTKm3kFZN6X3YVMAv xCP00bS9nViW8h4GxGMXnoe2kCiY6rfF30Hzgkcbv4/z0zYXFmYVg4OMqXYePRIs 5l3Je+s/q2kn5yP4hu82Ic6hdjob6FvXAty9oaRrigUKedvejHcnT2wyw1rFyiQP 6OETy+N9jb4FzoDqcdlThUdWV2n37clPbbpNQ8RJZLOTo26dkzjMgeNR1OJaAInZ BFfdqbYvGBCaLxkKNgxsumrbH17o31PkgCpm9lbYmTT0Qz6XEF1EG167UeAbGKhh Abhi2YQiWP1llWRaLjfqwstETkzWPo51mcqKBEiFtoC1eWALxk61gM34Se1zvYYH h0LxNjyB5a0y2BjDJ/P+M2Ma+1pGsBOFYAjEXKkSsRnUwwo91rs6p0OqJXFgWp7h Yot5pz37cTD6HjYVBV6U2fnShRM0bCasuX164YY1pY5mC8KLK7g= =shTo -----END PGP SIGNATURE-----