-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 22 Jun 2022 16:48:11 +0200 Source: maven-shared-utils Architecture: source Version: 3.3.4-1 Distribution: unstable Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Closes: 1012314 Changes: maven-shared-utils (3.3.4-1) unstable; urgency=high . * Team upload. * New upstream version 3.3.4. - Fix CVE-2022-29599: Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks. (Closes: #1012314) * Switch to debhelper-compat = 13. * Declare compliance with Debian Policy 4.6.1. * Drop 01-backward-compatibility.patch. * Build-depend on libcommons-text-java. Checksums-Sha1: 8c9db265509b3601946e07f32dadc1f680c6a0dd 2541 maven-shared-utils_3.3.4-1.dsc 6fa4551d67affe2a8af9fd6d4d60816336b0651f 114640 maven-shared-utils_3.3.4.orig.tar.xz 3ab6e107efc23f3c40cda9e948ffd4d3e90288e2 3352 maven-shared-utils_3.3.4-1.debian.tar.xz 3cc8b6051aa3d25fba53e5ab850c3321f7775410 15915 maven-shared-utils_3.3.4-1_amd64.buildinfo Checksums-Sha256: 1d2f969f6e2c4675a9c74155bb2d14190d3770e21736adcd9da0ee62956e78a1 2541 maven-shared-utils_3.3.4-1.dsc 9c70b29d6c176dd3319e4c5b799af1e4dda60ba320b27d8d25ee14c21c67f61b 114640 maven-shared-utils_3.3.4.orig.tar.xz 5aa5c58a3236b9f1b99ccaab3003fa1f8cb8d03e6e86495478b1f4fab8a94003 3352 maven-shared-utils_3.3.4-1.debian.tar.xz 6aa8dc1a2b0d604fdc693c0b997d2e9ef47e85cb8275b9bcad7fa2b1830990ca 15915 maven-shared-utils_3.3.4-1_amd64.buildinfo Files: 87d68d1262c33172178267a7a9c6a61d 2541 java optional maven-shared-utils_3.3.4-1.dsc 3876512550855c8cc91d6b254db9359b 114640 java optional maven-shared-utils_3.3.4.orig.tar.xz 91804b448676ba61b3243cde68cfb1b3 3352 java optional maven-shared-utils_3.3.4-1.debian.tar.xz ed93044aab844e7b64ede5bd24fd60d2 15915 java optional maven-shared-utils_3.3.4-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmKzP4dfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1Hkj44QAJDj683CYONiU/9xFl8RULHt3yB77lC69eOB 3fYkx+6hE1nQzuGjdWtpz6cs0Cmi3YRutH5CM29FBo0hajPdz+C/stW1Vep6kqOk GSY9LJm8eGZD1HcfptfQwTRdthvz4N3Na6dWe07GEI7WHfOIXxgo35iGfIQQxyz1 bmrh9T5/OzM+VN1m3RiqNGOumSpepkcyNYfWi4ZI+xzK29cSmXbzx6f1Exu96kvY PrRsrZx/xwUVHA6tcHWBJfc5TXVeieb8AgoaGjrNqH2mfeCIrwyLq0Y33ZNJAgGf zDKlh4CgfhJHL9Az17WdTpBGe0PzmdzlndpMBCMVQaf5+CHKqMK3j8TPn242Y/al U41vvS3DqNCxjdEOdaJyzIGIf1m9lOtmY+Fe+N9RxxhgdtRva/7Juxg6U3MZ19AJ yAhNHaMMIidPyQqemX4OQEj5di2sMcCqweSf+KOC+ENpJwdURmB7DqkQ1mlB2Ske 3SIo5epVS6Ip3BUy5rvaTnqNnOXyUGgYM7R0892Kp15zzHQhHGrlYc/uphjRfS7T vb2XY1YTYtKfSOOLiKEeliLtdUkfMAStpUB3rrIS3pvGCJo1a0F8yKsJLND6+agW 79n41N+VCHN801yO90H5dbw9fW0/6iDs43DVFtOhckHGDQrscAtgI4PTp2PZe0CF VrO3c9rA =oSvV -----END PGP SIGNATURE-----