-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA384 Format: 1.8 Date: Thu, 20 Oct 2022 18:11:04 +0200 Source: openjdk-8 Binary: openjdk-8-dbg openjdk-8-demo openjdk-8-doc openjdk-8-jdk openjdk-8-jdk-headless openjdk-8-jre openjdk-8-jre-headless openjdk-8-jre-zero openjdk-8-source Architecture: source Version: 8u352-ga-1 Distribution: unstable Urgency: medium Maintainer: Java Maintenance <debian-java@lists.debian.org> Changed-By: Thorsten Glaser <tg@mirbsd.de> Description: openjdk-8-dbg - Java runtime based on OpenJDK (debugging symbols) openjdk-8-demo - Java runtime based on OpenJDK (demos and examples) openjdk-8-doc - OpenJDK Development Kit (JDK) documentation openjdk-8-jdk - OpenJDK Development Kit (JDK) openjdk-8-jdk-headless - OpenJDK Development Kit (JDK) (headless) openjdk-8-jre - OpenJDK Java runtime, using openjdk-8-jre-headless - OpenJDK Java runtime, using (headless) openjdk-8-jre-zero - Alternative JVM for OpenJDK, using Zero/Shark openjdk-8-source - OpenJDK Development Kit (JDK) source files Changes: openjdk-8 (8u352-ga-1) unstable; urgency=medium . * Update GCC for bookworm/sid and kinetic-proposed from 11 to 12 to match default system compiler (this needs testing as people report early issues in other distros) * New upstream release * Security fixes: - JDK-8282252: Improve BigInteger/Decimal validation - JDK-8285662: Better permission resolution - JDK-8286511: Improve macro allocation - JDK-8286519: Better memory handling - JDK-8286526, CVE-2022-21619: Improve NTLM support - JDK-8286533, CVE-2022-21626: Key X509 usages - JDK-8286910, CVE-2022-21624: Improve JNDI lookups - JDK-8286918, CVE-2022-21628: Better HttpServer service - JDK-8288508: Enhance ECDSA usage * Other changes see https://mail.openjdk.org/pipermail/jdk8u-dev/2022-October/015706.html * Drop applied patches * Upload sponsored by ⮡ tarent Checksums-Sha1: 6a7744aff7462a67b382e8753719be584636ff67 4771 openjdk-8_8u352-ga-1.dsc 5bc11d4c207a51ba5cd822a13040b334c726be47 66175240 openjdk-8_8u352-ga.orig.tar.gz b6a2c3d68ad93d6350d303f875c345c8ce33ad15 180128 openjdk-8_8u352-ga-1.debian.tar.xz Checksums-Sha256: 802b113209736e47f8d3ee5cf5284a442bb2f9f93a99bc4f8b15f57f11148cf7 4771 openjdk-8_8u352-ga-1.dsc 071d5ea0c1fc620c7ead21d6bca94914dc36b9de603a4b097b9e875414e78123 66175240 openjdk-8_8u352-ga.orig.tar.gz 4ba1c4a3bf7badebf98f06c9a62636b174594cb47f815a8ad1980725f8f9e0fb 180128 openjdk-8_8u352-ga-1.debian.tar.xz Files: 1f680335d2d8512be09e660fb7d17c23 4771 java optional openjdk-8_8u352-ga-1.dsc 1f4573737e8e15a58792d200cff71915 66175240 java optional openjdk-8_8u352-ga.orig.tar.gz 2d475bc3446f66b8287ed61db218d201 180128 java optional openjdk-8_8u352-ga-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (MirBSD) iQIcBAEBCQAGBQJjVI95AAoJEHa1NLLpkAfgfHsQAKGoVvOzf7L4PJJqLT499kKH a2rU0jTPD6asq3XTH+fS8itgSHYn1DVH9nsVPIdxFhVq4ReGRz4erUiEKbwd5RUm 4KoVyn2ORGwtCBx55e5F93q9zBOaR8+uOgogeMaXh85ftPbTiBOUh/96tJa4XGwO HdXholo4creincAGshi498IcLHoqH3HCsXNlVqTlEArlIGvtMUpnjBH2+V/8INIG paGBrYv1hiRrn0Wwg9CkDGhEOW4gP+KQUaAt2KhniJf8Ai2sjv8JLQ+c2dQtGHMx t2bqQgvQSJFz9gH2xSAACeUbXj0WmDCXzeRAHsAYRl8YU1Azb9qexq4F2j/hNA3Q 4ULPFIZOkvh5etquSnSmdTW4ddjL2VHTtEGjA/8Hl7JSD5D7FqnWSBXJc/g2fHz1 M970xsMYi2D6AmNJ44VexV/09O1L5Agpa49F1Ew3Zgsaa6f0+MPN0ChYakAfmFsF IG8HPGlmyX7Ph6LSkHKK/nTYFF4b8fylHkvcf5uSne11JPN6gaLVc9qCSeo0qMyX 3YGzbe7sZRMcIdRRYHSwQml2a893lBjmoGsWlWY8RRSwf0kKBvKTt5vaXv/W2oC7 /3Js65lTCCb8QsccmcfVsH2xyXddR1+gOfmTyTeg48iMIfTxTywMv2CN0AGycR4r aYINTz6rJf7zrsDxTlXy =TqSZ -----END PGP SIGNATURE-----