-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 24 Mar 2020 14:03:07 +0100 Source: checkstyle Architecture: source Version: 8.15-1+deb10u1 Distribution: buster Urgency: medium Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Closes: 924598 Changes: checkstyle (8.15-1+deb10u1) buster; urgency=medium . * Team upload. * Fix CVE-2019-9658 and CVE-2019-10782: Security researchers from Snyk discovered that the fix for CVE-2019-9658 was incomplete. Checkstyle, a development tool to help programmers write Java code that adheres to a coding standard, was still vulnerable to XML External Entity (XXE) injection. (Closes: #924598) Checksums-Sha1: 780c4207e5ccd61c6f43e5d4e3252f7a19982ef5 2649 checkstyle_8.15-1+deb10u1.dsc 414732be7def78456c8799e43ba392739b50201c 10256 checkstyle_8.15-1+deb10u1.debian.tar.xz 90a1b7c7336a9ffdf8aa067f1952624345d0170c 16245 checkstyle_8.15-1+deb10u1_amd64.buildinfo Checksums-Sha256: 0d23dc41a6c92972ecc7d9f4c50b3052757859176022af25f5c526cd4e0d1d21 2649 checkstyle_8.15-1+deb10u1.dsc 5dc010290277e6f749edd1c82700a4bb7c7c6382d02614058ea2bab6b39f0de2 10256 checkstyle_8.15-1+deb10u1.debian.tar.xz 8da5fcdef39c203c49e16e5f02941459ac5035aa8ec26ac11add44ecf344aba9 16245 checkstyle_8.15-1+deb10u1_amd64.buildinfo Files: bdc7061003064666837d39a7c5ecab1d 2649 java optional checkstyle_8.15-1+deb10u1.dsc cca3c5077aa9eb187e3ce981196d1620 10256 java optional checkstyle_8.15-1+deb10u1.debian.tar.xz adcc0d6a4494bf4482707c84f48e932a 16245 java optional checkstyle_8.15-1+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAl56IKpfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkarkQAL0pmIQW6CFv2ZXd4ySWDd2tc1DY274tyd0U 6ORulZVP3MUs0lEfoCb16iGHpso0h+UqzrIDOimGi/AccbN215RJ9P662O8ggCQS 46/L3s84154fSwaCO2kMZ0vTR1Byfu0hGRZ1gV9C6BDZ7a61AOlkKuO50koehXNx f01gQQ5C03lAqqRzbN6ylXLtFMbSsYB5da5pPQS79TEGi6ZEp7FhFgEl8cJR31yp bBaCVhBahkk3dbj1Pj5Mw2NFzv2+gl6LEuE4wNhlkVYaixGwkk8xl5M3b5D56n1X xb4JAOIYsAKlaYjTa8AtDHZjZm6HGOuuvjFnrwaqS2tTTOwOUmiV2JsU2k3LfmCf XiE/vcboVmbOZ0m61xwmFPaUF6jNaCCYzYz4i1/KCAwvFoxJ7ehFAFJ030uE2rzU adz3QdkTM515n1dS6fOru+WXg0n9myTRUEDdbvVLviOsQ4EEbIoLUimIwhkHsGcW N8mcN4rvJZp7u1g+x5GoGi1o10nQY00r1+IllyslC9M1uVrW8f05u8bITUiQJCap DXhhxcABl0lp9SiFdLMtU8/1BwKqOroRY606m2w27rIY0AoWYd0VH8JKNVI9g+mR sAWs8YM1V4+dfJXjNnqqon9b8y1BCPHgj30ke0fTiVaOBtvNcE7xErvno5PegML2 jv9bmm8h =sckC -----END PGP SIGNATURE-----