Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities Ubuntu Security

USN-8768-1: Shibboleth vulnerability

A critical SQL injection vulnerability (CVE-2025-9943, CVSS 9.1) in Shibboleth's ODBC storage plugin allows remote attackers to obtain sensitive information via improper input escaping. The vulnerability affects multiple Ubuntu LTS releases, and fixes are provided via Ubuntu Pro's ESM channel for specific package versions listed in the USN. After applying the updates, a restart of the `shibboleth-sp` service is required.
Read Full Article →

Ubuntu Security Notices USN-8768-1 USN-8768-1: Shibboleth vulnerability Publication date 15 September 2026 Overview Shibboleth could be made to expose sensitive information over the network. Releases 24.04 LTS 22.04 LTS 20.04 LTS Open side navigation Close side navigation Packages Details Update instructions References Packages shibboleth-sp - Federated web single sign-on system Details Florian Stuhlmann discovered that Shibboleth incorrectly escaped input when using the ODBC storage plugin. A remote attacker could possibly use this issue to perform SQL injection attacks and obtain sensitive information. Florian Stuhlmann discovered that Shibboleth incorrectly escaped input when using the ODBC storage plugin. A remote attacker could possibly use this issue to perform SQL injection attacks and obtain sensitive information. Update instructions After a standard system update you need to restart shibboleth-sp to make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 24.04 LTS noble libshibsp11t64 – 3.4.1+dfsg-2.1ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. shibboleth-sp-common – 3.4.1+dfsg-2.1ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. shibboleth-sp-utils – 3.4.1+dfsg-2.1ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. 22.04 LTS jammy libshibsp10 – 3.3.0+dfsg1-1ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. shibboleth-sp-common – 3.3.0+dfsg1-1ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. shibboleth-sp-utils – 3.3.0+dfsg1-1ubuntu0.1~esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. 20.04 LTS focal libshibsp8 – 3.0.4+dfsg1-1ubuntu0.2+esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. shibboleth-sp-common – 3.0.4+dfsg1-1ubuntu0.2+esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. shibboleth-sp-utils – 3.0.4+dfsg1-1ubuntu0.2+esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. shibboleth-sp2-common – 3.0.4+dfsg1-1ubuntu0.2+esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. shibboleth-sp2-utils – 3.0.4+dfsg1-1ubuntu0.2+esm1 Ubuntu Pro Fix available with Ubuntu Pro via ESM Apps. A community fix might become publicly available in the future. Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2025-9943 CVE-2025-9943

Share this article