-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Fri, 07 Feb 2014 17:12:35 +0100 Source: libcommons-fileupload-java Binary: libcommons-fileupload-java libcommons-fileupload-java-doc Architecture: source all Version: 1.2.2-1+deb7u2 Distribution: wheezy-security Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Emmanuel Bourg <ebourg@apache.org> Description: libcommons-fileupload-java - File upload capability to your servlets and web applications libcommons-fileupload-java-doc - Javadoc API documentation for Commons FileUploads Changes: libcommons-fileupload-java (1.2.2-1+deb7u2) wheezy-security; urgency=high . * Team upload. * Fix CVE-2014-0050: Specially crafted input can trigger an infinite loop if the buffer used by the MultipartStream is not big enough. When constructing MultipartStream enforce the requirements for buffer size by throwing an IllegalArgumentException if the requested buffer size is too small. This prevents the DoS. * Enable the unit tests Checksums-Sha1: 26bb187457db31d6b4ca47a1db570ebcb922f111 2091 libcommons-fileupload-java_1.2.2-1+deb7u2.dsc ca98f223746257eb301f8b5e19eb91a26d66aa33 9255 libcommons-fileupload-java_1.2.2-1+deb7u2.debian.tar.gz 75b2145ce06e7b159bb2ff42f67795840e733919 55202 libcommons-fileupload-java_1.2.2-1+deb7u2_all.deb 544e3b4f1e549456070d87ca72fb4c79c8af3c71 369724 libcommons-fileupload-java-doc_1.2.2-1+deb7u2_all.deb Checksums-Sha256: 8a9eec433604921a16f7a58975f8eeb64bd35aafaa4c375f07e111f0557907d8 2091 libcommons-fileupload-java_1.2.2-1+deb7u2.dsc 7e5f691e7e14c04afda91fc762e9f5104b49d6dd2aaeb7761614d975a2742052 9255 libcommons-fileupload-java_1.2.2-1+deb7u2.debian.tar.gz 6f91742e500f062b5aef9dde55499aeb1779391ba7f71af2aeb4f02c75292fcc 55202 libcommons-fileupload-java_1.2.2-1+deb7u2_all.deb cfd3dc1c72fd2510e3398f10fd8e3e4108a20c5bace315c8db056bdaf68623a1 369724 libcommons-fileupload-java-doc_1.2.2-1+deb7u2_all.deb Files: 9f0c5475cfdc64d81f72380172dc3d92 2091 java optional libcommons-fileupload-java_1.2.2-1+deb7u2.dsc b61b2cedf8844c7a8919d48a328e7076 9255 java optional libcommons-fileupload-java_1.2.2-1+deb7u2.debian.tar.gz 241d68785016f9e252b9ac727565a1b6 55202 java optional libcommons-fileupload-java_1.2.2-1+deb7u2_all.deb cc7e50dc81c803f34140269c9aa4ed83 369724 doc optional libcommons-fileupload-java-doc_1.2.2-1+deb7u2_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJS9TKEAAoJEL97/wQC1SS+5AYH/i6/3o0Zl0POe8UhP4iPVB7j u2GHDOLL3Fpi9fCt91iCmIgz79uxpMrC8yi6JHS3mPxNRhYtolrPiY8NHRel3hiT 1lDvzBA3C/CTXdwqfJGWNVQi2uvNivf6iZKHFbwfJmazy23PR4cMzkqvbQPYfgc5 6G29d1Sj0785HcK2i52mKbHrUO4rFHSyUNj1c/hjYLrHCks+iqi4Es10aoTUGNS5 sTdUV50OxjEUFlgMO0dESCU3fFNlzIn0dEo5oCDRnKy+kN8PJzQoyXnO4KYO8VFd YgbHkUgCp2guSneTFi3D3Op38/bz6fHVJacsDB+ZYPQmqmVPvBDXCxf2eamNtQE= =HNzr -----END PGP SIGNATURE-----