-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 19 Sep 2020 20:20:21 +0100 Source: libjackson-json-java Architecture: source Version: 1.9.13-2 Distribution: unstable Urgency: medium Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Sudip Mukherjee <sudipm.mukherjee@gmail.com> Changes: libjackson-json-java (1.9.13-2) unstable; urgency=medium . * Team upload. * Add upstream fixes. - Serializing types for deeply nested Maps. - Set Secure Processing flag on DocumentBuilderFactory. - Set setExpandEntityReferences(false). (Fixes: CVE-2019-10172) - WriteRawValue surrogate pair fix. - Fix deserialization. - All known security fixes. (Fixes: CVE-2017-15095 and CVE-2017-7525) * Update Standards-Version to 4.5.0 * Use debhelper-compat. - Update compat level to 13. Checksums-Sha1: 4b19137686586989eca78b94b4ce568ec8680594 2402 libjackson-json-java_1.9.13-2.dsc 93037372d56d2db873d1f34ea06d0f1f67a5217a 10508 libjackson-json-java_1.9.13-2.debian.tar.xz 1d63835a173e068496d0ddcf5115dcad5b103df6 13588 libjackson-json-java_1.9.13-2_amd64.buildinfo Checksums-Sha256: 77a013df0190aec4169a4a19e483cbe8d6f1067bb1126c5b70e0775014162656 2402 libjackson-json-java_1.9.13-2.dsc 8706c0385617bd5674be4814e47ae09e0068f1150f731e7aaecf456bcf313c55 10508 libjackson-json-java_1.9.13-2.debian.tar.xz 81bee626c5b9010ef9bda711725a029c268706b709ed9e00bb0a784544dc5dcf 13588 libjackson-json-java_1.9.13-2_amd64.buildinfo Files: d33ecc45e52e1b33a5095cef5bbe48b1 2402 java optional libjackson-json-java_1.9.13-2.dsc 3efbf028d95de6b21bedb366c97ef89a 10508 java optional libjackson-json-java_1.9.13-2.debian.tar.xz bcc255eaf055664323eaa393fd82be47 13588 java optional libjackson-json-java_1.9.13-2_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEuDQJkCg9jZvBlJrHR5mjUUbRKzUFAl9mX5cACgkQR5mjUUbR KzVk6Q//bXsG3hGmNUzzJncdVKTyVYQ5r3u8mwkhIGjHcyGIHaeFmxg9nqOZLCIU l0NKXk4N5FPAsbJ3BWmoGuaS2EAyEN97Bpe2NxXUMn0wf8eWJn5apQkPrPiHR+h2 NQKGKZE6zqBJiJlxZ4U3zXhcBy3xgh+8y/t4Tr8d6yQMDOzpjubU6+U3dhPeHwwb +wxWbC8y6W5miz9wS7UtEZymL5ZhTDjho6FAAl+js97/Jq9bOWWlTGKYVT87KGx+ GaJbEJDmVv5MMnkGMcT0qPJHfHmgWtrya7W8LIRBAJ/EkLEVDFhGtIn746sQYn19 TsKZxcnPQYTQar4SvlEihaVyU1kDLrMeSHoC3Qoza1t6sJ+GFD3lH6IXhhG+qyF7 DUiQoRCc3k18EDqcKRwBqR2JLDi4l496UT154XtdwbfP6sRchrvTP5Hoqd+nbEfQ 5z/IPxc9JbShkFcZPlI2cY5ek2dRktbsnfx68lNoPGaEbfsjIjC3OuEqgmCShRRV i3Xk4S4TDD3wwHU57VffwA2dJOJj1+7yuzmmIhzsiyxCS/aK5ucMbo5TR1wV6W7e 2E48xkWio/42+p1a9x2Ju1sTRpz8g0Itr1207mLYZZuahlvaVcHL9944D4TgCcKE mi8IMKuE/Tfi3pu8rStjav+QzrXtcXeWaFOY5iz55RK+1BYDGnk= =102Z -----END PGP SIGNATURE-----