-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 03 Jul 2021 20:40:52 +0200 Source: libxstream-java Binary: libxstream-java Architecture: source Version: 1.4.11.1-1+deb9u3 Distribution: stretch-security Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Sylvain Beucler <beuc@debian.org> Description: libxstream-java - Java library to serialize objects to XML and back again Changes: libxstream-java (1.4.11.1-1+deb9u3) stretch-security; urgency=high . * Non-maintainer upload by the LTS Security Team. * CVE-2021-29505: a remote attacker may get sufficient rights to execute commands of the host only by manipulating the processed input stream. Checksums-Sha1: aa19424fcd9c3bf9b6e9e172f0d46db375455445 2435 libxstream-java_1.4.11.1-1+deb9u3.dsc e487c99d65f7a3b72cf92574774d7ddd6e86f4b4 14444 libxstream-java_1.4.11.1-1+deb9u3.debian.tar.xz 53edf6dfe3b0ebe3ffb04dec9c247c90f3b57dc6 16143 libxstream-java_1.4.11.1-1+deb9u3_all.buildinfo Checksums-Sha256: 1d9e30e5f422a9148389dd997045705883036b1527b5b2465a32948022afafda 2435 libxstream-java_1.4.11.1-1+deb9u3.dsc f5ae099ed94b1fd8fa6a77bf9b06bcc7034c1384dab3aa44bcc7f39dc5dee4f2 14444 libxstream-java_1.4.11.1-1+deb9u3.debian.tar.xz 3eb2c41ea11593477868d6b5712e3f8ddb1b24e2b823c09aeb4147e73ed67fc9 16143 libxstream-java_1.4.11.1-1+deb9u3_all.buildinfo Files: ae439c065c068cab4c2bfd65ff3612db 2435 java optional libxstream-java_1.4.11.1-1+deb9u3.dsc ebdf8f09b82c990acbd929cf47593477 14444 java optional libxstream-java_1.4.11.1-1+deb9u3.debian.tar.xz dea13ca5a16d5262ea940ac8f5479fea 16143 java optional libxstream-java_1.4.11.1-1+deb9u3_all.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE1vEOfV7HXWKqBieIDTl9HeUlXjAFAmDjJsAACgkQDTl9HeUl XjAXgw//fNsLFACWvehlW3gJ63aZiYAzWM05Uq3MLC7dVlEoMwldsLgMrL3V/7i/ eFZibODlreogEkfExTz4vGIyYZzYHZDNpqKcQHuHUij3V1yoFRea9pmpySTIZcQR HjinSFsIs80kEetNUU7yX0xrB5WkzXuaQX6FqqoZG9F47feB8tChBru0nbcgui+Z QG8XezjK8SH7vjOHuldnrrv1zesXSfvv1NZEvLCPAlaHl70xjkpaBylgpJD4YhXE F+r4FyjHvI8GrUeYEsRqUDgGNfSRgE4i6Nk7f9VFQutM0lp1NBCgpK2egMuOQhi+ 4cuJzQG0VpqBO5m6UC7dM+TIxeQt1ev38wVYoEOUF5wY528CRIgtybq9J6JeTeuc VLcapH0vjGRNOxBCo+6sJrYmGi368VhK1uzu+h1TPS0ljKDzz9+0eWyIMRVCRCLv vvfgwq5R7IA+oYPAAPyko/ZaZsNUyLjW/SpJyxsf2EestBOZPjrXSIZRMADewrmR qJa4l/6Ya3u3nWDdwuXE5vXl8vYyogVOO5yZRvwl8PSq4EQLt0TDeg8joJ1jLxjF 0MqfFOiupml2eeM74VztuHBQzLQe21QDxqBDt0eyEk4rdK8JeMSwIgRXOk8rxglY XBdPTG14Ixr4y0QFTrL4mitmZgnMyq7FY7egVwR7ewCJZANNioM= =NRtx -----END PGP SIGNATURE-----