-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 10 Feb 2020 12:37:58 +0100 Source: checkstyle Binary: checkstyle checkstyle-doc Architecture: source all Version: 5.9-1+deb8u2 Distribution: jessie-security Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: checkstyle - checks Java source against a coding standard checkstyle-doc - Documentation for Checkstyle Changes: checkstyle (5.9-1+deb8u2) jessie-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2019-10782: Security researchers from Snyk discovered that the fix for CVE-2019-9658 was incomplete. Checkstyle, a development tool to help programmers write Java code that adheres to a coding standard, was still vulnerable to XML External Entity (XXE) injection. Checksums-Sha1: 73faca44632a6f9506d1bacb1a38413e88e2c79f 2630 checkstyle_5.9-1+deb8u2.dsc 938a7761a2e5d19ad838ed074b2df84011d09b5e 9648 checkstyle_5.9-1+deb8u2.debian.tar.xz a80c6c6c1776a112fea2a60e45229a2af9509fcb 648676 checkstyle_5.9-1+deb8u2_all.deb da8e41dc1c84a4686ca104b393c31ad85b105a21 857566 checkstyle-doc_5.9-1+deb8u2_all.deb Checksums-Sha256: d0b92a4889e130a8f78b21f24036f5369449a4a2e6dd9bc69a8a10abda0a60e0 2630 checkstyle_5.9-1+deb8u2.dsc 3ab52599104790d0932df15991a20069aa7444cda2919468c35b21d71b5c859b 9648 checkstyle_5.9-1+deb8u2.debian.tar.xz 2b43759393c87bc1af2374a50c5db121b74bd6362424c4784b22de7a79015255 648676 checkstyle_5.9-1+deb8u2_all.deb d1552c90b6993425679aecb83b1b1f35fd2dd353c72cfe4016b4fa4e569a2019 857566 checkstyle-doc_5.9-1+deb8u2_all.deb Files: 3ede8501de693422fecc8c126302cb14 2630 java optional checkstyle_5.9-1+deb8u2.dsc f6166b5953602a2c43f7ea98d2ec1d5b 9648 java optional checkstyle_5.9-1+deb8u2.debian.tar.xz cc410eb0c1777d19f1deed846e4cb355 648676 java optional checkstyle_5.9-1+deb8u2_all.deb 7ffe12c8c1f8accfa5ca4d95fabfc33f 857566 doc optional checkstyle-doc_5.9-1+deb8u2_all.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl5BVihfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1Hk1fcP/1qKqN6JgYIwx9w3OvgRvQLATlZ4epMXz0p+ swsIYzQJzMrJDUumE9mwCKYB/w+dqI5xD48m62zGiBwi30wsrdNAiH2GFHixcrBM axsSV29NiwFOBuhPo5HouMhj2AlFVZT8j+CDyDJuG9Jjr1hdBm0rO5qjmBPNoP/R a5JTOZDWU6ZI5MU/4s4COLCQimRNubCQIf69X3mHgYzBfJZkfvBoy1lHMfu/7h92 YPQvhe8hVWj+qpGJdeLvo1vR9za28HWHn0yyenpfDy/q2pIddTrBOaKwfZhWH1Vi eCvMOxdZINGaQB9eYKyiNh7K46/Qw0pAVUwRTBGsl1do6M8RpFNKTbiCc8tYRlOi M0j79hDHxbIKCn2n22lW0fWsAcDnChSwLIvXzka6EIwqG943Rbj/1nL8DEPnSDMd 0PDRLp9u2Y31dkgFOrYIhJ/x5jsXebT8gzttdMVgIAJdAi6jL0I8B8JGsLhhxdo+ TNWYrqe/oj+0bEGU4fQS/pjqO0HE9zpjcZgmpWPhWfG6i/NyTfR/bQEKmstWkeZr ota9aJXabG56YGknId1ADaXNCacSikLk07JlASSsSWITmtcb2bT/MIOJiPZ3Y8zr va0vQlY5faHbyKrgiS4lZHEfp1BvCwr1z51I6juXg11QLIbOC4DJt0jFwRpO2zt+ 4OvCT8/j =JK5D -----END PGP SIGNATURE-----