-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 26 Nov 2015 18:21:28 +0100 Source: libcommons-collections3-java Binary: libcommons-collections3-java libcommons-collections3-java-doc Architecture: source all Version: 3.2.1-4+deb6u1 Distribution: squeeze-lts Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Santiago Ruano Rincón <santiagorr@riseup.net> Description: libcommons-collections3-java - A set of abstract data type interfaces and implementations libcommons-collections3-java-doc - Documentation for libcommons-collections3-java Changes: libcommons-collections3-java (3.2.1-4+deb6u1) squeeze-lts; urgency=high . * Cherry-picking changes made in wheezy: [ Emmanuel Bourg ] * Backported a modification from commons-collections 3.2.2 disabling the deserialization of the functors classes unless the system property org.apache.commons.collections.enableUnsafeSerialization is set to true. This fixes a vulnerability in unsafe applications deserializing objects from untrusted sources without sanitizing the input data. Checksums-Sha1: 0f02fe46996150e065b286d53338a1474cedfa69 2196 libcommons-collections3-java_3.2.1-4+deb6u1.dsc cf430d63d9cebf0a6f4e6ce4327769cd6254a7b7 7077 libcommons-collections3-java_3.2.1-4+deb6u1.diff.gz 7a7c89bc41ea406928df3d880fb7bbe720aaa742 606378 libcommons-collections3-java_3.2.1-4+deb6u1_all.deb f0b497835db700313a216357a4dad75d112440cd 891606 libcommons-collections3-java-doc_3.2.1-4+deb6u1_all.deb Checksums-Sha256: 2f987ade3262d023ab017424442f294ba6cf66b305d60c719fd3e31e959c23e3 2196 libcommons-collections3-java_3.2.1-4+deb6u1.dsc f8ccaa5f4c3bfa46f7a9410e3e7272d619165c5c4d2a1bca600d218057237ae8 7077 libcommons-collections3-java_3.2.1-4+deb6u1.diff.gz dbbb9d8d4005f4b436af380f5fff76cc28bc89cc00b0df1b2e6eeab9166568f4 606378 libcommons-collections3-java_3.2.1-4+deb6u1_all.deb 9ce9060bba7f3c20ee286f84e22204a8a5f03f370b7271d8110b5e817d5b0c32 891606 libcommons-collections3-java-doc_3.2.1-4+deb6u1_all.deb Files: 0f201c7ec405720b13def56b7226289a 2196 java optional libcommons-collections3-java_3.2.1-4+deb6u1.dsc d44c6f7e49b9b3f375d567f9b84fcea4 7077 java optional libcommons-collections3-java_3.2.1-4+deb6u1.diff.gz 0fa6bd2513456f97e03aeef78360b631 606378 java optional libcommons-collections3-java_3.2.1-4+deb6u1_all.deb 52a3dd3abb273bf9859f8514cc6e0c5a 891606 doc optional libcommons-collections3-java-doc_3.2.1-4+deb6u1_all.deb -----BEGIN PGP SIGNATURE----- iQIcBAEBCgAGBQJWV1VHAAoJEN5v/bjI1ki9fsIP/1YGy508Rykp7vOM/UMXw4P1 HlCHqZMPwFHS/BOp9UqtWhjyukUxfQA82AJeQ9q0lk4cGwof+YP1dy3cxK28CrRI jO6LSndA5V9R+E/FORGVrffIFVRiuFmzsFwaW+DCI6KSZq5gkCpVW5Gt+DCau2Lb dUT3SnE8igrWZ8hld8trTrGIv/kT5JNMLZH/fQZAvLv6+5RspDcH1coLuzsFiBFb nNbQqeoomNz1m5x50R+mqAHVSzO7zPBOp9Ytjdw1TLRxcNvitkxHqAr5/EWSOYkz Fp6Mv1Lcvibmz1eF8xQkSJFOMgdBBmP5XCuBuGvF/KHz03ZuBd32fW8QySjoGMNi 1Q6NOmfYVZshu8Zt5Egqvw0TUrPkMmtIs2Zn3nTGWlzukjVe8dCTuKJiRKZhFt3y a7z9FJJn3IJI7z5JgTCk+wHzwMtPAHscrtVqwjUAFDRnpYuw7YRO5AeDQH6m5j6l cg4PB2qKWM2+WQVrgeFuEbqCS8328Z+7lDzIFnFc4YcIxF9DuUViJTC9ywDES8qo sAP4vT+YugB+MpJdPb0BMH7S58cARou3jEIzl6IM3RksYP21yzdRg4qhjKnIHpZA H41ITWOuBt1gY/7HNWH0NXgJpHmVCBlb1WiqZ1wdqy+JBYXZUolaaErjgk6MUXWb w3CQwMJj7GwUcikanYSF =fdKj -----END PGP SIGNATURE-----