Bug 58813 - lasso: Multiple issues (5.2)
Summary: lasso: Multiple issues (5.2)
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Security updates
Version: UCS 5.2
Hardware: All Linux
: P3 normal
Target Milestone: UCS 5.2-3-errata
Assignee: Quality Assurance
QA Contact: Iván.Delgado
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2025-11-17 13:00 CET by Quality Assurance
Modified: 2025-11-20 13:19 CET (History)
2 users (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score: 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) NVD


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2025-11-17 13:00:53 CET
New Debian lasso 2.8.1-1+deb12u1 fixes:
This update addresses the following issues:
2.8.1-1+deb12u1 (Fri, 07 Nov 2025 21:51:12 +0100)
* Non-maintainer upload by the Security Team.
* tests: test that inserted comment do not change node value and still  validate signature
* xml: prevent assignment of attribute value inside any attribute  (CVE-2025-47151)
* misc: check xmlSecGetNodeNsHref for possible NULL result (CVE-2025-46404)
* xml: do not terminate on an unknown XML node type (CVE-2025-46705)
Comment 1 Quality Assurance univentionstaff 2025-11-17 14:00:17 CET
--- mirror/ftp/pool/main/l/lasso/lasso_2.8.1-1+b1A~5.2.0.202305190934.dsc
+++ apt/ucs_5.2-0-errata5.2-3/source/lasso_2.8.1-1+deb12u1.dsc
@@ -1,8 +1,12 @@
-2.8.1-1+b1A~5.2.0.202305190934 [Fri, 19 May 2023 10:20:18 +0200] Univention builddaemon <buildd@univention.de>:
+2.8.1-1+deb12u1 [Fri, 07 Nov 2025 21:51:12 +0100] Salvatore Bonaccorso <carnil@debian.org>:
 
-  * UCS auto build. The following patches have been applied to the original source package
-    00_ftbfs.patch
-    10_expose_lasso_provider_verify_saml_signature.quilt
+  * Non-maintainer upload by the Security Team.
+  * tests: test that inserted comment do not change node value and still
+    validate signature
+  * xml: prevent assignment of attribute value inside any attribute
+    (CVE-2025-47151)
+  * misc: check xmlSecGetNodeNsHref for possible NULL result (CVE-2025-46404)
+  * xml: do not terminate on an unknown XML node type (CVE-2025-46705)
 
 2.8.1-1 [Wed, 01 Mar 2023 08:36:25 +0100] Frederic Peters <fpeters@debian.org>:
 

<http://piuparts.knut.univention.de/5.2-3/#4952862154127316513>
Comment 2 Quality Assurance univentionstaff 2025-11-18 13:01:28 CET
--- mirror/ftp/pool/main/l/lasso/lasso_2.8.1-1+b1A~5.2.0.202305190934.dsc
+++ apt/ucs_5.2-0-errata5.2-3/source/lasso_2.8.1-1+deb12u1~5.2.3.202511181226.dsc
@@ -1,4 +1,4 @@
-2.8.1-1+b1A~5.2.0.202305190934 [Fri, 19 May 2023 10:20:18 +0200] Univention builddaemon <buildd@univention.de>:
+2.8.1-1+deb12u1~5.2.3.202511181226 [Tue, 18 Nov 2025 12:45:34 -0000] Univention builddaemon <buildd@univention.de>:
 
   * UCS auto build. The following patches have been applied to the original source package
     00_ftbfs.patch

<http://piuparts.knut.univention.de/5.2-3/#7970110815763978208>
Comment 3 Iván.Delgado univentionstaff 2025-11-18 13:19:00 CET
OK: bug
OK: yaml
OK: announce_errata
OK: patch
OK: piuparts

[5.2-3] 7f5420763b chore(lasso): create advisory for 2.8.1-1+deb12u1~5.2.3.202511181226
 doc/errata/staging/lasso.yaml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

[5.2-3] b3dbf00c7b chore(lasso): create advisory for 2.8.1-1+deb12u1
 doc/errata/staging/lasso.yaml | 17 +++++++++++++++++
 1 file changed, 17 insertions(+)
Comment 4 Julia Bremer univentionstaff 2025-11-18 14:19:14 CET
This breaks SAML login:

python3: unable to dlopen /usr/lib/x86_64-linux-gnu/sasl2/libsaml.so: /usr/lib/x86_64-linux-gnu/sasl2/libsaml.so: undefined symbol: lasso_provider_verify_saml_signature
Comment 5 Julia Bremer univentionstaff 2025-11-18 14:50:01 CET
(In reply to Quality Assurance from comment #2)
> --- mirror/ftp/pool/main/l/lasso/lasso_2.8.1-1+b1A~5.2.0.202305190934.dsc
> +++
> apt/ucs_5.2-0-errata5.2-3/source/lasso_2.8.1-1+deb12u1~5.2.3.202511181226.dsc
> @@ -1,4 +1,4 @@
> -2.8.1-1+b1A~5.2.0.202305190934 [Fri, 19 May 2023 10:20:18 +0200] Univention
> builddaemon <buildd@univention.de>:
> +2.8.1-1+deb12u1~5.2.3.202511181226 [Tue, 18 Nov 2025 12:45:34 -0000]
> Univention builddaemon <buildd@univention.de>:
>  
>    * UCS auto build. The following patches have been applied to the original
> source package
>      00_ftbfs.patch
> 
> <http://piuparts.knut.univention.de/5.2-3/#7970110815763978208>

This shows patch > -    10_expose_lasso_provider_verify_saml_signature.quilt was not applied to the new version
Comment 6 Quality Assurance univentionstaff 2025-11-19 10:01:26 CET
--- mirror/ftp/pool/main/l/lasso/lasso_2.8.1-1+b1A~5.2.0.202305190934.dsc
+++ apt/ucs_5.2-0-errata5.2-3/source/lasso_2.8.1-1+deb12u1A~5.2.3.202511190929.dsc
@@ -1,8 +1,18 @@
-2.8.1-1+b1A~5.2.0.202305190934 [Fri, 19 May 2023 10:20:18 +0200] Univention builddaemon <buildd@univention.de>:
+2.8.1-1+deb12u1A~5.2.3.202511190929 [Wed, 19 Nov 2025 09:29:40 -0000] Univention builddaemon <buildd@univention.de>:
 
   * UCS auto build. The following patches have been applied to the original source package
     00_ftbfs.patch
     10_expose_lasso_provider_verify_saml_signature.quilt
+
+2.8.1-1+deb12u1 [Fri, 07 Nov 2025 21:51:12 +0100] Salvatore Bonaccorso <carnil@debian.org>:
+
+  * Non-maintainer upload by the Security Team.
+  * tests: test that inserted comment do not change node value and still
+    validate signature
+  * xml: prevent assignment of attribute value inside any attribute
+    (CVE-2025-47151)
+  * misc: check xmlSecGetNodeNsHref for possible NULL result (CVE-2025-46404)
+  * xml: do not terminate on an unknown XML node type (CVE-2025-46705)
 
 2.8.1-1 [Wed, 01 Mar 2023 08:36:25 +0100] Frederic Peters <fpeters@debian.org>:
 

<http://piuparts.knut.univention.de/5.2-3/#5682229496916516281>
Comment 7 Iván.Delgado univentionstaff 2025-11-20 11:42:03 CET
OK: bug
OK: yaml
OK: announce_errata
OK: patch
OK: piuparts

[5.2-3] ae14a696f6 chore(lasso): create advisory for 2.8.1-1+deb12u1A~5.2.3.202511190929
 doc/errata/staging/lasso.yaml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

[5.2-3] 7f5420763b chore(lasso): create advisory for 2.8.1-1+deb12u1~5.2.3.202511181226
 doc/errata/staging/lasso.yaml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

[5.2-3] b3dbf00c7b chore(lasso): create advisory for 2.8.1-1+deb12u1
 doc/errata/staging/lasso.yaml | 17 +++++++++++++++++
 1 file changed, 17 insertions(+)
Comment 8 Christian Castens univentionstaff 2025-11-20 13:19:43 CET
<https://errata.software-univention.de/#/?erratum=5.2x291>