-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 07 Nov 2025 21:51:12 +0100 Source: lasso Binary: liblasso-perl liblasso-perl-dbgsym liblasso3 liblasso3-dbgsym liblasso3-dev python3-lasso python3-lasso-dbgsym Architecture: mips64el Version: 2.8.1-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-03) Changed-By: Salvatore Bonaccorso Description: liblasso-perl - Library for Liberty Alliance and SAML protocols - Perl bindings liblasso3 - Library for Liberty Alliance and SAML protocols - runtime library liblasso3-dev - Library for Liberty Alliance and SAML protocols - development kit python3-lasso - Library for Liberty Alliance and SAML protocols - Python bindings Changes: lasso (2.8.1-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * tests: test that inserted comment do not change node value and still validate signature * xml: prevent assignment of attribute value inside any attribute (CVE-2025-47151) * misc: check xmlSecGetNodeNsHref for possible NULL result (CVE-2025-46404) * xml: do not terminate on an unknown XML node type (CVE-2025-46705) Checksums-Sha1: 44f6ce0101b35cbe859a43ca3f22f997893ae63c 10941 lasso_2.8.1-1+deb12u1_mips64el-buildd.buildinfo c5b5ec6342d84c56c74b97caadc2ed8fa9df479d 217568 liblasso-perl-dbgsym_2.8.1-1+deb12u1_mips64el.deb aefea81cf14ab798b542e0c84c620071ffeb3261 680752 liblasso-perl_2.8.1-1+deb12u1_mips64el.deb 938b61100af24b96f8c1bcf60cb6729d35b28981 820928 liblasso3-dbgsym_2.8.1-1+deb12u1_mips64el.deb b8c951371c9cdd10a57cc89638609d99af00de56 887588 liblasso3-dev_2.8.1-1+deb12u1_mips64el.deb 0fdcb6f1712bd7864fddfe794966c942c53321dc 756212 liblasso3_2.8.1-1+deb12u1_mips64el.deb 14d9b86ef8bac3d91b61aa64c92360169b570a29 354336 python3-lasso-dbgsym_2.8.1-1+deb12u1_mips64el.deb a733ad507db63351b402772f51c7ffdeaeb9dfc8 714132 python3-lasso_2.8.1-1+deb12u1_mips64el.deb Checksums-Sha256: d05fbf196900a925a07c3b9ef3e9ab87ad541f5020d45136ecb4237dc884c507 10941 lasso_2.8.1-1+deb12u1_mips64el-buildd.buildinfo 113c84d7f46266521497b4f90cba0a2db48c3fdb81059b508fbfc3b8818ede62 217568 liblasso-perl-dbgsym_2.8.1-1+deb12u1_mips64el.deb ccc396cb318679c0cb339efb309e0cdc6b0e9f53a6d5969fd73e379a28b7330c 680752 liblasso-perl_2.8.1-1+deb12u1_mips64el.deb 95268def403945faabcbb32199092759f948413d329d5c335481c12635ca033e 820928 liblasso3-dbgsym_2.8.1-1+deb12u1_mips64el.deb 1e2ed404d966f8accfa60b889232c924c7fc3eb4f030d2b27c5e23a8f33d9bb2 887588 liblasso3-dev_2.8.1-1+deb12u1_mips64el.deb baedc39b81f1d72a33418e015e82828dafb25bfb2f6c6611da936e0bf172650f 756212 liblasso3_2.8.1-1+deb12u1_mips64el.deb a1e5f5112df148a10f6a2eac0aea7510027953d2007c484525beed91e4155d10 354336 python3-lasso-dbgsym_2.8.1-1+deb12u1_mips64el.deb 08b942f025eb6b02b0007fec7a2d4ef142d754d0517bf865cd1ab9c9ca6338c4 714132 python3-lasso_2.8.1-1+deb12u1_mips64el.deb Files: f0b050b585ca859175070965772a4895 10941 libs optional lasso_2.8.1-1+deb12u1_mips64el-buildd.buildinfo e4ca11d1bef974b2e1ac3d31507a1016 217568 debug optional liblasso-perl-dbgsym_2.8.1-1+deb12u1_mips64el.deb 030cc5adff6ab77a27203ecec0ae625b 680752 perl optional liblasso-perl_2.8.1-1+deb12u1_mips64el.deb 0d89921297cf0a7bd12ac5deaa6553cb 820928 debug optional liblasso3-dbgsym_2.8.1-1+deb12u1_mips64el.deb 1a260bd016a648509dbd7e74aace33e0 887588 libdevel optional liblasso3-dev_2.8.1-1+deb12u1_mips64el.deb b5b40d61d1a848f550b050a1365d3fc9 756212 libs optional liblasso3_2.8.1-1+deb12u1_mips64el.deb 80942b2d6dc37f86f82a7faf0dd98642 354336 debug optional python3-lasso-dbgsym_2.8.1-1+deb12u1_mips64el.deb 3523c228fb3c501a216203c9545e7795 714132 python optional python3-lasso_2.8.1-1+deb12u1_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEesE3YcWKZXIkRPMemf85J+x5/aoFAmkST9gACgkQmf85J+x5 /aqoWA//ZzMw5IQLZFLo+NLDgDQpY+4e784K4FTKGrRTQ+jqeCi9VYlwXcWFvl1C Eo/c55DeqkDjQihSsOn4nNktpfl9OLQk3O0q3Gqwr5ofYuw+5jGRaeqmYN7PGTi8 mPJenVAvLbD6kTZDTM8UGUV3YDEukJ+ZsAOB7f9eyvsHzkZSm++a48V3GHryYsST hhpkoeoMI1lCa1ZXmd+Bt1t3eSab8GE7VXAl7fxjB7WM7mqTTidxOnUopQdKcEhl TgIhyi5G8axJxaUtIQnPb53Jpf3byrV11RX+u6FveW5YzK+6WkXyH9r9h1ACSIfM iArL8RzaIaFIpHZRMOe54fpWESv7lUgJWpIkQTpJzjI7AG7eIn7lhIPJ+r6S1ISU OfdUbTtUqU6sZ9k40/QLKssYDjJNT46vInJuv9ok0JeZdqTLCqtYMDcsqgBCZNa0 pNved9YtUuevlH3L3HyalVwsDOGiCuozEinR27Tm4fsNLSO1FTEdtfvsivJv3Krh QzvG2bvikTy/BdQyspmPPWJlYpCNzGUfG4E4dOLaBSOFXQ6ICiC6S50qpYCZkvDJ 1xpm3TilTVuibAZQmjXgkXf/IuKYUIDbOHl4pnCGm9R0V+pjsMKE2fXvKSEY3ZfY ZjwzrOC6CXub0kS8OOMvG0422h+4yq+PWoogyMkx4USXpdPgPMs= =6WDI -----END PGP SIGNATURE-----