-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 18 Mar 2016 22:24:17 +0100 Source: activemq Binary: libactivemq-java libactivemq-java-doc activemq Architecture: source all Version: 5.6.0+dfsg1-4+deb8u2 Distribution: jessie-security Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: activemq - Java message broker - server libactivemq-java - Java message broker core libraries libactivemq-java-doc - Java message broker core libraries - documentation Changes: activemq (5.6.0+dfsg1-4+deb8u2) jessie-security; urgency=high . * Team upload. * Fix CVE-2015-5254: Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object. Checksums-Sha1: b3312d29b72e5edec8b4c9f303ed200c1da11c05 3508 activemq_5.6.0+dfsg1-4+deb8u2.dsc 4c3f1adde69b0df895d38fc4e95bfc9eabcbc8bf 22408 activemq_5.6.0+dfsg1-4+deb8u2.debian.tar.xz a13b5e725f7ac288b840c1fdd322b6cf88afaffb 3588878 libactivemq-java_5.6.0+dfsg1-4+deb8u2_all.deb 0c153cb60152e0107a90dcd32810d3edc41cb492 3500488 libactivemq-java-doc_5.6.0+dfsg1-4+deb8u2_all.deb 0e109048e85765593f4b4bc221d96d441b9a67c3 49442 activemq_5.6.0+dfsg1-4+deb8u2_all.deb Checksums-Sha256: 750edc31ddb34cf3d5d16c7f103818f03d706deb84375ec2349fc48fac70c4e8 3508 activemq_5.6.0+dfsg1-4+deb8u2.dsc 8ba0476ed158357643fe26e6869aa07766509436bac786db52b33dea0bf4897d 22408 activemq_5.6.0+dfsg1-4+deb8u2.debian.tar.xz 40909c5c9c1f52999b155557bee6cb4ca6f9961c79199fc43ec391f8cf50f3c3 3588878 libactivemq-java_5.6.0+dfsg1-4+deb8u2_all.deb 7b6835cd85dbc6efb203ed67ec8a0f3ae2933210dc5616769cc30dcef70b550a 3500488 libactivemq-java-doc_5.6.0+dfsg1-4+deb8u2_all.deb 01e12c90c97406cb538bb7e24a5a5de9634bd966affe39d3a68d5d885548f37b 49442 activemq_5.6.0+dfsg1-4+deb8u2_all.deb Files: 19d02aa7c61838fe62953d9df6386c1d 3508 java optional activemq_5.6.0+dfsg1-4+deb8u2.dsc d385e5a73741893c5c3c941c2fb7d523 22408 java optional activemq_5.6.0+dfsg1-4+deb8u2.debian.tar.xz d7e229fff8976c4cac51a48cfccda2f5 3588878 java optional libactivemq-java_5.6.0+dfsg1-4+deb8u2_all.deb dbfac0ee39a199134a99344a1ae5311f 3500488 doc optional libactivemq-java-doc_5.6.0+dfsg1-4+deb8u2_all.deb bea7cd721c5310c72ce96c6c46e2b471 49442 java optional activemq_5.6.0+dfsg1-4+deb8u2_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQJ8BAEBCgBmBQJW7Hc0XxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRBQ0YzRDA4OEVGMzJFREVGNkExQTgzNUZE OUFEMTRCOTUxM0I1MUU0AAoJENmtFLlRO1HkQtIQALWk7z5jD3BTmPRk0qKPTdRS jCZdOrUz8XCjWTHj+5feXpbKguuhv/CgU5qddGbMAYA/HFtpyB3PxIqKHAqiFWPN Xihocrm0DmwiPVwIuB8R0MpSapGMwrmq46dwqAdMln1/asFUDrYE01ud8tjVu7TV 9f3Yjs00DB0hSW3jyjTxa2VmlUb++Uw63tOgbsVTD6g7QUM1aVtAK6Qewd9SMKbG FIfRvECopF4WOyp2WkFAKA2k2+bFHZsfBWvwRvcpR+mIcABqCZvQPbYT5CE2p/lc bRpEU+laIo3s0K4vxxbYgJViN885c4zzjXATmfj6pI7om8nVrSDbDCY/plqzZD0R o3e5lmOwaCR5szP90YFlpC5ierf5q7Ht/N/r/sOXFHD5E6us4pGbtJZ5VnvpxCnb /qNRYxzFHSgU+rONlh3I4fMhs9wMgaA2qdiRArJnD9PLkQ7r+vh0vm1FitUs5zHr AllkM3MLU6a5/yfoC+z8m2rK0erGAoBTnqK7MpERRvHXViDcfR4Nws40YmQZ0a1m 3Rei1qXOhVCqXoY1QHUjmfZ7aPceShKDCZOTRPwkttgAdVpuw0IrULA7CkR/u/Y/ KF5FbDJhQ2bsilFfozTkhuJ4RdSMayLShIuCEEae0xBCKhFrbMyTxtm3ljqi61+r zItQkFrq6vEb7I3fAbfw =TWuh -----END PGP SIGNATURE-----