-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 18 Mar 2016 22:47:35 +0100 Source: activemq Binary: libactivemq-java libactivemq-java-doc activemq Architecture: source all Version: 5.6.0+dfsg-1+deb7u2 Distribution: wheezy-security Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: activemq - Java message broker - server libactivemq-java - Java message broker core libraries libactivemq-java-doc - Java message broker core libraries - documentation Changes: activemq (5.6.0+dfsg-1+deb7u2) wheezy-security; urgency=high . * Team upload. * Fix CVE-2015-5254: Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object. Checksums-Sha1: ab880c49f8b55b30072fb6009b85610965b58b4c 3468 activemq_5.6.0+dfsg-1+deb7u2.dsc 393b37ddd5423781e8a7ea8807161d323e76aba3 43066 activemq_5.6.0+dfsg-1+deb7u2.debian.tar.gz 905d8a7e14cd39f4098b68de51c739babd3472b1 4014852 libactivemq-java_5.6.0+dfsg-1+deb7u2_all.deb 6a366a4986d747bbad8d0e7e1d55120734880c3a 9125304 libactivemq-java-doc_5.6.0+dfsg-1+deb7u2_all.deb fe289f1c4e3696f3d50c083e4c618460b29d2627 53566 activemq_5.6.0+dfsg-1+deb7u2_all.deb Checksums-Sha256: 779d454658afcdca8a84a6fdf8f04c87855c509267b5851e8d1c78379ca1ab8b 3468 activemq_5.6.0+dfsg-1+deb7u2.dsc ba29e7b66ce36912e5e7253c59fe4c3d009fcacb7993cb77ad39b946af9951d3 43066 activemq_5.6.0+dfsg-1+deb7u2.debian.tar.gz 19bb646b79d90fcf25b87ff52b6d2a9662c120c89a7dfbcc86236cf9d1fc72fb 4014852 libactivemq-java_5.6.0+dfsg-1+deb7u2_all.deb ae4f0fb8ec8b28835352c2a5c279f1a5d83c8d8b016e03ac88a277bc5fc4b24a 9125304 libactivemq-java-doc_5.6.0+dfsg-1+deb7u2_all.deb 819395b0a2e0bdb491ec6e69fa4b9e421a5c920fc87872e337be8d9e901fcc5b 53566 activemq_5.6.0+dfsg-1+deb7u2_all.deb Files: 976ec40254b1ab054fd0ae37005236c9 3468 java optional activemq_5.6.0+dfsg-1+deb7u2.dsc 6bd48730408c3b3a564e5a03604f56a5 43066 java optional activemq_5.6.0+dfsg-1+deb7u2.debian.tar.gz bd3c7c0fd6f43929f299038d85516782 4014852 java optional libactivemq-java_5.6.0+dfsg-1+deb7u2_all.deb 267fea8d96fbe0fc91b7001d8d6bf1f3 9125304 doc optional libactivemq-java-doc_5.6.0+dfsg-1+deb7u2_all.deb 8821d2167b126ddfb2ab4a4d05a531bb 53566 java optional activemq_5.6.0+dfsg-1+deb7u2_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQJ8BAEBCgBmBQJW7HppXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRBQ0YzRDA4OEVGMzJFREVGNkExQTgzNUZE OUFEMTRCOTUxM0I1MUU0AAoJENmtFLlRO1HkqWgQAJNGKihvosot6UA2DhuwEdNz f9oc0/NL0swYoyjdJmNM2p3MAVagi1mIQJOCoatqWyVxkJcBcrH4e51NDrguIeUh EOXsyiuBPOYfo/tShOuHQ/0g6Nw5hpDyS0Ql+pqPZx/FAlGgaprBt9FbN/pTkE9j bVSlVJYRhwLbMo2K/7Xt4b+6faHdpkYF+geZmWdUpdVB7AoaqNw0gmTPW9UfwTin Vpg7ML9YIzx8gwx4Nofr5hmQ3awqI+TS/kp/XwHC72gckGY8siYddz2HnE6jLP8A 9CYx8v2uE4PoTKjbQ1zw9yDzJAXlw+N7k9TQPpP1oEHtsu3bjwGnvYXVdReezV6y 7/0Ixyc+hmdAft3nNDTZ5nhtuMfL9uOd0XouHH96KfQT26SA1+lkbSxVLyGbHHI4 D7uIibiHpZm9nskwXo4RQYyvyQSTlCLwK0fro2RRwuad4A6Il1qG2hSBcoit4ksu YGhX/8Ae4yoSe4P2nORPIfXNK2PG/qNPypgf3TZR37x6Y9WlRa4yHx2XnRmGGA8r 1NS0UKZqoLLrpLnFoCBDpQY/5OmazGRRwEGGGmphCSPQkUUH+ZOc1/P+P1Us2FZT keGcuGnXPnzFDlc3MWtTPg2jlE5alRYws1gFYc9kZqjjlq5e8p/iblmYqEbTX018 pwOG9Yw+MlKcRIn7nR1r =4/y7 -----END PGP SIGNATURE-----