Back to xmlbeans PTS page

Accepted xmlbeans 2.6.0+dfsg-1+deb9u1 (source) into oldstable



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 28 Jun 2021 14:26:03 +0200
Source: xmlbeans
Binary: libxmlbeans-java xmlbeans
Architecture: source
Version: 2.6.0+dfsg-1+deb9u1
Distribution: stretch-security
Urgency: high
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: Markus Koschany <apo@debian.org>
Description:
 libxmlbeans-java - Java library for accessing XML by binding it to Java types
 xmlbeans   - Java library for accessing XML by binding it to Java types - tool
Changes:
 xmlbeans (2.6.0+dfsg-1+deb9u1) stretch-security; urgency=high
 .
   * Non-maintainer upload by the LTS team.
   * Fix CVE-2021-23926:
     The XML parsers used by XMLBeans did not set the properties needed to
     protect the user from malicious XML input. Vulnerabilities include
     possibilities for XML Entity Expansion attacks.
   * Compile for source/target 1.5 in order to fix a compilation failure.
Checksums-Sha1:
 a68223f462865bdff1f08c0230d368d878c6d5b1 2331 xmlbeans_2.6.0+dfsg-1+deb9u1.dsc
 9eb1fc0964768ae6313500fb314b1a30602ae71a 2063766 xmlbeans_2.6.0+dfsg.orig.tar.gz
 9714bd085f9eec106c246270847b9b01babbdeff 14768 xmlbeans_2.6.0+dfsg-1+deb9u1.debian.tar.xz
 f21b0f14e6a06d48efdf35af28b3171bbe1f9cda 11889 xmlbeans_2.6.0+dfsg-1+deb9u1_amd64.buildinfo
Checksums-Sha256:
 7fef0beaa5fe8fca83d85eed01661ab1670e930a78bee1efa0dbb7e113c2104b 2331 xmlbeans_2.6.0+dfsg-1+deb9u1.dsc
 f758b2fad0249719e9859696866a1c6cc6c0fc9ee6f74532d1078f68c6d0265a 2063766 xmlbeans_2.6.0+dfsg.orig.tar.gz
 364a0cbe19cf212ba8f711edf497ca30e21c6212bbb35ae81e74134e93be7bec 14768 xmlbeans_2.6.0+dfsg-1+deb9u1.debian.tar.xz
 73d6f766a791642212dbb11a3edc30b21b77472049c3b46e27b11d4d6aa317d3 11889 xmlbeans_2.6.0+dfsg-1+deb9u1_amd64.buildinfo
Files:
 d6eff6eea7b7cb8e8394edcb2d9cda5f 2331 java optional xmlbeans_2.6.0+dfsg-1+deb9u1.dsc
 f8a42472f251b0468b181814b3d1b317 2063766 java optional xmlbeans_2.6.0+dfsg.orig.tar.gz
 0b274074ceb0b80582f953d0e96034de 14768 java optional xmlbeans_2.6.0+dfsg-1+deb9u1.debian.tar.xz
 38468032a2a5e715fb8567e823374b02 11889 java optional xmlbeans_2.6.0+dfsg-1+deb9u1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmDZykBfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD
RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp
YW4ub3JnAAoJENmtFLlRO1HkCA4P/ieaUNFbS4vvDOD5+bQFJztUmQpZDOxBgl/5
J6BIz8EP6/6U7viFH+xefY+PnMAaOj8R4mr19QSXRY3TGUWbfSOO/AY6bPta1FF0
ZaRJ4m3K4vk4PYCxGvu0wFHoeb5rPgywSY6BV4GNgwtrH1sMx15YFzO9zskwQ0Hc
ace2wTnABhGOAGgUuf4zQIV0Vs4ZjbBT6zV+4R9DAq11AID0tauZ2gjs0Z/KZzJZ
uy9j5eyZKlwGTlE5lId2jq++LtzIcGaJPXrL3KlxaWVjoLH++eG69CbiyXYNXh6p
Rxo2l/3BLefyZC9ouf8358xJ1wGezllNT3s/rSCMf7gdUubJFjLFA1Q91W7HLEpU
UjTUsvSUiE3DAgddcrpNdscOwXKfw18TQ/G5E6yuOY+NxkKx8m4ag5k1UmJ7L/aR
MnsZWkhgUBM3iJSV3dt9x7bgEvTmybLMxY3/BjQKlXvHkxMpAvZVxRf4qQhw+tr/
kUAlJlcD9YEYFro/XT6YRFZTuPkQIxkcFRo/qBX3SV77Hiib8pRNVncX+O+l4GAv
18pcLo13buWXmJYuVAKVy/nljHk3TKKdbGHGNhp6A2iuk65lDC/TDxwKna8SlTyr
BLTO+1c//galPi7N31PPQbA+AT6uzMTDu6JC4KkeDnlzmHwmoO7LP0ycVF5LpP9x
jfUsji10
=B6ez
-----END PGP SIGNATURE-----