Debian Package Tracker
Register | Log in
Subscribe

libcommons-lang-java

Commons Lang - an extension of the java.lang package

Choose email to subscribe with

general
  • source: libcommons-lang-java (main)
  • version: 2.6-10
  • maintainer: Debian Java Maintainers (archive) (DMD)
  • uploaders: Emmanuel Bourg [DMD]
  • arch: all
  • std-ver: 4.6.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 2.6-9
  • stable: 2.6-10
  • testing: 2.6-10
  • unstable: 2.6-10
versioned links
  • 2.6-9: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.6-10: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libcommons-lang-java
  • libcommons-lang-java-doc
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2025-48924: Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Created: 2025-07-11 Last update: 2025-07-16 14:32
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2025-48924: Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Created: 2025-07-11 Last update: 2025-07-16 14:32
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2025-48924: Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Created: 2025-07-11 Last update: 2025-07-16 14:32
lintian reports 12 warnings normal
Lintian reports 12 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2020-07-29 Last update: 2024-02-28 15:04
Multiarch hinter reports 1 issue(s) low
There are issues with the multiarch metadata for this package.
  • libcommons-lang-java-doc could be marked Multi-Arch: foreign
Created: 2016-09-14 Last update: 2025-07-31 18:00
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2025-48924: (needs triaging) Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

You can find information about how to handle this issue in the security team's documentation.

Created: 2025-07-11 Last update: 2025-07-16 14:32
debian/patches: 1 patch to forward upstream low

Among the 2 debian patches available in version 2.6-10 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-02-26 15:54
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.6.1).
Created: 2022-12-17 Last update: 2025-02-27 13:25
news
[rss feed]
  • [2022-05-28] libcommons-lang-java 2.6-10 MIGRATED to testing (Debian testing watch)
  • [2022-05-23] Accepted libcommons-lang-java 2.6-10 (source) into unstable (Emmanuel Bourg)
  • [2019-09-18] libcommons-lang-java 2.6-9 MIGRATED to testing (Debian testing watch)
  • [2019-09-13] Accepted libcommons-lang-java 2.6-9 (source) into unstable (Emmanuel Bourg)
  • [2018-04-04] libcommons-lang-java 2.6-8 MIGRATED to testing (Debian testing watch)
  • [2018-03-30] Accepted libcommons-lang-java 2.6-8 (source) into unstable (Emmanuel Bourg)
  • [2018-01-17] libcommons-lang-java 2.6-7 MIGRATED to testing (Debian testing watch)
  • [2018-01-12] Accepted libcommons-lang-java 2.6-7 (source) into unstable (Emmanuel Bourg)
  • [2015-11-23] libcommons-lang-java 2.6-6 MIGRATED to testing (Britney)
  • [2015-11-17] Accepted libcommons-lang-java 2.6-6 (source all) into unstable (Markus Koschany)
  • [2015-05-17] libcommons-lang-java 2.6-5 MIGRATED to testing (Britney)
  • [2015-05-11] Accepted libcommons-lang-java 2.6-5 (source all) into unstable (Emmanuel Bourg)
  • [2014-01-16] libcommons-lang-java 2.6-4 MIGRATED to testing (Debian testing watch)
  • [2014-01-10] Accepted libcommons-lang-java 2.6-4 (source all) (Emmanuel Bourg)
  • [2011-12-14] libcommons-lang-java 2.6-3 MIGRATED to testing (Debian testing watch)
  • [2011-12-04] Accepted libcommons-lang-java 2.6-3 (source all) (Damien Raude-Morvan)
  • [2011-12-03] Accepted libcommons-lang-java 2.6-2 (source all) (Ludovic Claude) (signed by: Damien Raude-Morvan)
  • [2011-08-13] libcommons-lang-java 2.6-1 MIGRATED to testing (Debian testing watch)
  • [2011-08-03] Accepted libcommons-lang-java 2.6-1 (source all) (Miguel Landaeta) (signed by: tony mancill)
  • [2009-08-20] libcommons-lang-java 2.4-4 MIGRATED to testing (Debian testing watch)
  • [2009-08-09] Accepted libcommons-lang-java 2.4-4 (source all) (Torsten Werner)
  • [2009-07-20] Accepted libcommons-lang-java 2.4-3 (source all) (Ludovic Claude) (signed by: Torsten Werner)
  • [2009-07-12] Accepted libcommons-lang-java 2.4-2 (source all) (Torsten Werner)
  • [2008-05-19] libcommons-lang-java 2.4-1 MIGRATED to testing (Debian testing watch)
  • [2008-05-08] Accepted libcommons-lang-java 2.4-1 (source all) (Kumar Appaiah)
  • [2008-01-16] libcommons-lang-java 2.3-4 MIGRATED to testing (Debian testing watch)
  • [2008-01-05] Accepted libcommons-lang-java 2.3-4 (source all) (Michael Koch)
  • [2008-01-04] Accepted libcommons-lang-java 2.3-3 (source all) (Michael Koch)
  • [2007-10-11] libcommons-lang-java 2.3-2 MIGRATED to testing (Debian testing watch)
  • [2007-09-30] Accepted libcommons-lang-java 2.3-2 (source all) (Michael Koch)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 12)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.6-10

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing