-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 21 Apr 2021 14:51:39 +0200 Source: libhibernate3-java Architecture: source Version: 3.6.10.Final-9+deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Changes: libhibernate3-java (3.6.10.Final-9+deb10u1) buster-security; urgency=high . * Team upload. * Fix CVE-2020-25638: A flaw was found in hibernate-core. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SQL comments of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity. Checksums-Sha1: e6bcc15833713d4c434e78a3a44d078c56d2cf9b 2941 libhibernate3-java_3.6.10.Final-9+deb10u1.dsc c06bac1c1aad0219391b93d115eb85a191740c01 11164 libhibernate3-java_3.6.10.Final-9+deb10u1.debian.tar.xz f55362a591c4bbb824199547904c6be05c7453bf 13673 libhibernate3-java_3.6.10.Final-9+deb10u1_amd64.buildinfo Checksums-Sha256: 2caee4966557a81d7f8892cbd288bb01c0bc107e01837a0ad2c138dfbada2452 2941 libhibernate3-java_3.6.10.Final-9+deb10u1.dsc 405b82c185fec8ec3d6be6fabb01972c3d5a4527221048be34ab67bc59a6bbd2 11164 libhibernate3-java_3.6.10.Final-9+deb10u1.debian.tar.xz d9c0c1322cc06962a40bc05c4c250f1239169dad71c4b79ca9495033a5d9d9db 13673 libhibernate3-java_3.6.10.Final-9+deb10u1_amd64.buildinfo Files: a699cc97dcc7b9f39b29772c30102f13 2941 java optional libhibernate3-java_3.6.10.Final-9+deb10u1.dsc e01e6d38c5a1ca8bf2b24315deb73a55 11164 java optional libhibernate3-java_3.6.10.Final-9+deb10u1.debian.tar.xz 2f29781cffb79fe6c137f4b26b76cee9 13673 java optional libhibernate3-java_3.6.10.Final-9+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmCGkqlfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1Hk4boP/j1PUp2FK8CAEpL/7mYvzVuFqpa9JiZjbyuE 4HEzVqBBHxF+YIpo1GVxHVoNRgMdA/SrJlv2ctxqPWKU+NRMeXNKtnWXdr6yReRw MxXqU5eT5tx+4a6bqWVCmPbA37hd7m5697eH5b7iEr/dpfnMP+a9yI2XRJ+xsPAy Fa42NCupFb6COqDJLeLbUF6eeuBf/0fP01nEcuTEzQIbVUIaX9btRMGydtmRa2GF HGGNAbMD8LUK/hossaRrAuN4F5NSuY+m29rO/mOalobJPS3mXQEvsTe+28zIMFUd LO571kHCKyJIOa7oa2ATP6nw2yrI+WSkpBfhxlLn3684BwTTGGdS+Ng678BtCIIX 0Bytww3Ex+p+1PLcXnDeqA0sGydBEcbi/H9gcjHzcTmULPt5ic+hzyYoW06o2rkC EVY+KTnWkHEuuISiLPG30FDWc0I+acFrWQZucpBn5bjmw3Wh/JCXzyEeDZC/ln5b KeKvZnQ2H/7eYi9yWzI6i2fu183esaBfOJ53nn52A8Ucb0upXRiBikkjRl1ioYGX jbcC/iXEfUN8BGphqwHr+O5PLliLM9l2oRDU3csAXWAZlow7w3HmMJUorJqBpTav zW0XZ1gQ7ioM0UTL9ywNopyUEiOMENEoja++z2E7WH+x+xN+a36+xx3c3NCTBg1j kXS4PnAp =Av4v -----END PGP SIGNATURE-----