-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA384 Format: 1.8 Date: Fri, 05 Nov 2021 23:57:58 +0000 Source: openjdk-8 Architecture: source Version: 8u312-b07-1 Distribution: unstable Urgency: medium Maintainer: Java Maintenance <debian-java@lists.debian.org> Changed-By: Thorsten Glaser <tg@mirbsd.de> Changes: openjdk-8 (8u312-b07-1) unstable; urgency=medium . * New upstream release (GA) * Security fixes: - JDK-8130183, CVE-2021-35588: InnerClasses: VM permits wrong Throw ClassFormatError if InnerClasses attribute's inner_class_info_index is 0 - JDK-8161016: Strange behavior of URLConnection with proxy - JDK-8163326, CVE-2021-35550: Update the default enabled cipher suites preference - JDK-8254967, CVE-2021-35565: com.sun.net.HttpsServer spins on TLS session close - JDK-8263314: Enhance XML Dsig modes - JDK-8265167, CVE-2021-35556: Richer Text Editors - JDK-8265574: Improve handling of sheets - JDK-8265580, CVE-2021-35559: Enhanced style for RTF kit - JDK-8265776: Improve Stream handling for SSL - JDK-8266097, CVE-2021-35561: Better hashing support - JDK-8266103: Better specified spec values - JDK-8266109: More Resilient Classloading - JDK-8266115: More Manifest Jar Loading - JDK-8266137, CVE-2021-35564: Improve Keystore integrity - JDK-8266689, CVE-2021-35567: More Constrained Delegation - JDK-8267086: ArrayIndexOutOfBoundsException in java.security.KeyFactory.generatePublic - JDK-8267712: Better LDAP reference processing - JDK-8267729, CVE-2021-35578: Improve TLS client handshaking - JDK-8267735, CVE-2021-35586: Better BMP support - JDK-8268193: Improve requests of certificates - JDK-8268199: Correct certificate requests - JDK-8268506: More Manifest Digests - JDK-8269618, CVE-2021-35603: Better session identification - JDK-8269624: Enhance method selection support - JDK-8270398: Enhance canonicalization - JDK-8270404: Better canonicalization * Other changes: see https://mail.openjdk.java.net/pipermail/jdk8u-dev/2021-October/014373.html * Policy 4.6.1, no relevant changes * d/copyright: Apply changes since 8u302 * Upload sponsored by ⮡ tarent Checksums-Sha1: 5f5dd5e1deeefe7de26de7165ef5b78c096ceed1 4778 openjdk-8_8u312-b07-1.dsc d29e777029531859318e5450491d066f1f4f4b27 73598246 openjdk-8_8u312-b07.orig.tar.gz c2e5a266b49557d49ac423f739daf1bd05a609c9 176044 openjdk-8_8u312-b07-1.debian.tar.xz Checksums-Sha256: fd46194332c2a5402a1723feacb2d5cce2dfdc35d2f21a06e108bb6080bcaee2 4778 openjdk-8_8u312-b07-1.dsc 6923b17ac84ef7416470f046ece3386736fa438a2fd4b9fd6fa164e55880a44b 73598246 openjdk-8_8u312-b07.orig.tar.gz 309be10c76332d6b04d2d78ca2afd63287c784ea2295a1d3c26222d4c2e6c24a 176044 openjdk-8_8u312-b07-1.debian.tar.xz Files: a900e57936007a48319ddfbfcef329fb 4778 java optional openjdk-8_8u312-b07-1.dsc cf8f455e54b1efa20d66e04bcbb632f4 73598246 java optional openjdk-8_8u312-b07.orig.tar.gz 896b7f3a4c9b8e8374ac5df529c800b4 176044 java optional openjdk-8_8u312-b07-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (MirBSD) Comment: ☃ ЦΤℱ—8 ☕☂☄ iQIcBAEBCQAGBQJhhflqAAoJEHa1NLLpkAfgm2gP/R0T8Nu7tzVD7j69PIwS+E9i TBb+ZjMsrPePPXv/BIPthA1wngMsOO6VIF2VDd/zAS4VIbXWMCgdn9G/oOJQV8cW ovmqcgUVgwbx4kx+CU8SQHVECa8mVZBJ3nz36vR0/HRR2eWZO//+vfUwmHeB4TkV xZMijNt/CHlAZR03iRGhzRY0c6H/QNmUTPUKiC/rYsMnFeJ1n5Sl1Y71JFY9U2FB FmCFlVcLihR+Jh7y1VZAJCPgIyEFxckqNrU59qX5UCmvuWpqaGxeu6/PWU5OBbG0 2yCh9COs4UJ+/z5xvR4OM7rYC5d6l65JSMkxhT2BD7mG5D1ZL3T9CN3eUYEtki4Z O3nw+4IWI9xw/4OhTlojrqm8ptzfWuD/OR1KdWSlRunp9RpAJe9JP0M04YCE7jrM yb1pVegquxp5wVk35i2ap+DEKtDC1GuQZkr3kRX7DmO7uocqSuDZHqkAGn6Xj9Wv v+YOx397iK6gCYCwbB8gK5F9zswRfc1jeBmEbiSswonJ1yRzHBlVihUNa2jX6VBH 9WNpKuXqtWPa//OBDcNLADGR5sPaaLykYGtsKi3F4uUy/Br98DGGnlduqkJ0CRfi M5Da1asOlyIXo5PII84nMj54trR9jZQGrQKuN7YkSbUgCMc6nI1FFH7xB6AKehD9 4RwivuroKWQsXvdK/20T =tEt0 -----END PGP SIGNATURE-----