-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 07 Nov 2025 21:51:12 +0100 Source: lasso Binary: liblasso-perl liblasso-perl-dbgsym liblasso3 liblasso3-dbgsym liblasso3-dev python3-lasso python3-lasso-dbgsym Architecture: mipsel Version: 2.8.1-1+deb12u1 Distribution: bookworm-security Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Salvatore Bonaccorso Description: liblasso-perl - Library for Liberty Alliance and SAML protocols - Perl bindings liblasso3 - Library for Liberty Alliance and SAML protocols - runtime library liblasso3-dev - Library for Liberty Alliance and SAML protocols - development kit python3-lasso - Library for Liberty Alliance and SAML protocols - Python bindings Changes: lasso (2.8.1-1+deb12u1) bookworm-security; urgency=high . * Non-maintainer upload by the Security Team. * tests: test that inserted comment do not change node value and still validate signature * xml: prevent assignment of attribute value inside any attribute (CVE-2025-47151) * misc: check xmlSecGetNodeNsHref for possible NULL result (CVE-2025-46404) * xml: do not terminate on an unknown XML node type (CVE-2025-46705) Checksums-Sha1: 16572afd5f6fd6c3699ebc5e20aa511cb3b1613d 10888 lasso_2.8.1-1+deb12u1_mipsel-buildd.buildinfo 768ee0a5416fa5c631ea30e94a7e3adbc0a60a67 174896 liblasso-perl-dbgsym_2.8.1-1+deb12u1_mipsel.deb 1ef8bdc1da7d272ce31c58191f422ba1aaebf284 681508 liblasso-perl_2.8.1-1+deb12u1_mipsel.deb fe3a6e4a02ed3190aa680a517367cd7d2495ebe2 796680 liblasso3-dbgsym_2.8.1-1+deb12u1_mipsel.deb c9b3659706983826cca148a7e35a7e9c56b050b9 887028 liblasso3-dev_2.8.1-1+deb12u1_mipsel.deb 5c4ba42a4d40417bf1f002f5db773b55fd6952ed 758460 liblasso3_2.8.1-1+deb12u1_mipsel.deb ae5d3cfd2c4d8e76f3b3a2ab7ed5acafa8e9051d 347288 python3-lasso-dbgsym_2.8.1-1+deb12u1_mipsel.deb 186a83287d29e02bc426313691d332f25e8c8cf5 715044 python3-lasso_2.8.1-1+deb12u1_mipsel.deb Checksums-Sha256: c34f1b7dc48fe6fdfe2433e125727c6d0969840391bf1c8a61cfd94bbb859fcf 10888 lasso_2.8.1-1+deb12u1_mipsel-buildd.buildinfo 3811f04711ea728023b734cacac2395045d368f07c4153f5e2f178c20b3f2738 174896 liblasso-perl-dbgsym_2.8.1-1+deb12u1_mipsel.deb 6112d582be593983c82d4eb9dfa48de3f56fd5a17296df5577eabc4b1f597cd5 681508 liblasso-perl_2.8.1-1+deb12u1_mipsel.deb 7c7b8d7dffc6721168cec050f21db828fc192df24f265285bd80b389cce3645d 796680 liblasso3-dbgsym_2.8.1-1+deb12u1_mipsel.deb eed79b2e5ffd59a6d1bbfcb60cda13647058d50b95c49c8ca120635919f3c068 887028 liblasso3-dev_2.8.1-1+deb12u1_mipsel.deb 6dc2035427fb93c496ff12a332e91b7904c9f1098ea952ac39f8cfdca6b1a3ae 758460 liblasso3_2.8.1-1+deb12u1_mipsel.deb 3ee30762e39258671157e098031cf5899c1f7a8a6ed75820c0da55a4974460ab 347288 python3-lasso-dbgsym_2.8.1-1+deb12u1_mipsel.deb 55586595533f6dba4319f6127d9802a17a23ff64267f6c95ab1ed53291a7df83 715044 python3-lasso_2.8.1-1+deb12u1_mipsel.deb Files: d47c0671af9c508760c26991db5976bf 10888 libs optional lasso_2.8.1-1+deb12u1_mipsel-buildd.buildinfo 20a8eabb65249d12584bb926b58466e6 174896 debug optional liblasso-perl-dbgsym_2.8.1-1+deb12u1_mipsel.deb 674712e1eb21294d07c86883314c4279 681508 perl optional liblasso-perl_2.8.1-1+deb12u1_mipsel.deb b15b17777d26e51c8e28e4aa7c8d080f 796680 debug optional liblasso3-dbgsym_2.8.1-1+deb12u1_mipsel.deb 268820817106958095af5a39d1a79852 887028 libdevel optional liblasso3-dev_2.8.1-1+deb12u1_mipsel.deb bb5186dad578f997cff9c5c6979518f5 758460 libs optional liblasso3_2.8.1-1+deb12u1_mipsel.deb d5b986cc2e7841efa507b4a065cbe1fb 347288 debug optional python3-lasso-dbgsym_2.8.1-1+deb12u1_mipsel.deb f911b8c2e7fbc31d853f74c81ab17097 715044 python optional python3-lasso_2.8.1-1+deb12u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEYLhEzFkGpb3yYRVHmlVdU6AM9BUFAmkST/UACgkQmlVdU6AM 9BX1GBAAuqNB+QnI7zq3u/p6NC/vwVyLnZwCJS9LiEpXpS+hRkxkqhjZMwE7L0Ly pJjGf7xHY7yW53g1LRKMHXwI+C0rPrUfm73VNxdYQkyDM2nVSJ5trz/7Dk2PpYVC o5qdMD6JVzHwHaVEkvtTIVJff1a1dMyj0bZSvcszKhFF+zIk6Hr/iqp7cHwjK5I/ lgs7V9jFHByLNit2rNg5+GqOQpnH1GbdF+wUvnLMF68IG/kZWwGlRZCK3hjKiLL0 CAO+oJ3XrnZz3ek/YU7m2ZO54KoOr8jxCFo0Mn53MFke03V/7TFaQ+8x9jn7dSrh nKplG+8qUV5Vs2HfpkjcF6+syprHJtQWKRiFta5PMQi2o9N1yWBiJ9xU/zicxK/U Bxaa2vbPZ/HPYaesHDL70B2lKDXFq6UlGCoU5rRz9YByzlenq6zqTpnf33tQV851 vqUDaseaww4XApj31H53Iod8JA5mOz2XsuwedMXk8YeCY85NSuJlHO5S4hV7cUhU pIDkKVuaCxPuKqb9176Y/O1WTHAsXiq7nr4PzvMIhAWmNH5VQ7hOP+/LTMclnzbG OwSJVGJ8eY2bshI4jzpOAtbJRkyA9KfJG6eBdCGbIrW9J9xGLdkFh1VVQH0oqGEG bJZoX8ATw2QjT4uTY3FOeCokVcr5avPm1Kh3X16yRue03D9eUaM= =9Foe -----END PGP SIGNATURE-----