Accepted libxstream-java 1.4.11.1-1+deb9u3 (source) into oldstable
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 03 Jul 2021 20:40:52 +0200
Source: libxstream-java
Binary: libxstream-java
Architecture: source
Version: 1.4.11.1-1+deb9u3
Distribution: stretch-security
Urgency: high
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: Sylvain Beucler <beuc@debian.org>
Description:
libxstream-java - Java library to serialize objects to XML and back again
Changes:
libxstream-java (1.4.11.1-1+deb9u3) stretch-security; urgency=high
.
* Non-maintainer upload by the LTS Security Team.
* CVE-2021-29505: a remote attacker may get sufficient rights to execute
commands of the host only by manipulating the processed input stream.
Checksums-Sha1:
aa19424fcd9c3bf9b6e9e172f0d46db375455445 2435 libxstream-java_1.4.11.1-1+deb9u3.dsc
e487c99d65f7a3b72cf92574774d7ddd6e86f4b4 14444 libxstream-java_1.4.11.1-1+deb9u3.debian.tar.xz
53edf6dfe3b0ebe3ffb04dec9c247c90f3b57dc6 16143 libxstream-java_1.4.11.1-1+deb9u3_all.buildinfo
Checksums-Sha256:
1d9e30e5f422a9148389dd997045705883036b1527b5b2465a32948022afafda 2435 libxstream-java_1.4.11.1-1+deb9u3.dsc
f5ae099ed94b1fd8fa6a77bf9b06bcc7034c1384dab3aa44bcc7f39dc5dee4f2 14444 libxstream-java_1.4.11.1-1+deb9u3.debian.tar.xz
3eb2c41ea11593477868d6b5712e3f8ddb1b24e2b823c09aeb4147e73ed67fc9 16143 libxstream-java_1.4.11.1-1+deb9u3_all.buildinfo
Files:
ae439c065c068cab4c2bfd65ff3612db 2435 java optional libxstream-java_1.4.11.1-1+deb9u3.dsc
ebdf8f09b82c990acbd929cf47593477 14444 java optional libxstream-java_1.4.11.1-1+deb9u3.debian.tar.xz
dea13ca5a16d5262ea940ac8f5479fea 16143 java optional libxstream-java_1.4.11.1-1+deb9u3_all.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmDjJsAACgkQDTl9HeUl
XjAXgw//fNsLFACWvehlW3gJ63aZiYAzWM05Uq3MLC7dVlEoMwldsLgMrL3V/7i/
eFZibODlreogEkfExTz4vGIyYZzYHZDNpqKcQHuHUij3V1yoFRea9pmpySTIZcQR
HjinSFsIs80kEetNUU7yX0xrB5WkzXuaQX6FqqoZG9F47feB8tChBru0nbcgui+Z
QG8XezjK8SH7vjOHuldnrrv1zesXSfvv1NZEvLCPAlaHl70xjkpaBylgpJD4YhXE
F+r4FyjHvI8GrUeYEsRqUDgGNfSRgE4i6Nk7f9VFQutM0lp1NBCgpK2egMuOQhi+
4cuJzQG0VpqBO5m6UC7dM+TIxeQt1ev38wVYoEOUF5wY528CRIgtybq9J6JeTeuc
VLcapH0vjGRNOxBCo+6sJrYmGi368VhK1uzu+h1TPS0ljKDzz9+0eWyIMRVCRCLv
vvfgwq5R7IA+oYPAAPyko/ZaZsNUyLjW/SpJyxsf2EestBOZPjrXSIZRMADewrmR
qJa4l/6Ya3u3nWDdwuXE5vXl8vYyogVOO5yZRvwl8PSq4EQLt0TDeg8joJ1jLxjF
0MqfFOiupml2eeM74VztuHBQzLQe21QDxqBDt0eyEk4rdK8JeMSwIgRXOk8rxglY
XBdPTG14Ixr4y0QFTrL4mitmZgnMyq7FY7egVwR7ewCJZANNioM=
=NRtx
-----END PGP SIGNATURE-----