-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Wed, 01 Jun 2016 08:31:37 +0200 Source: libpdfbox-java Binary: libpdfbox-java libpdfbox-java-doc libjempbox-java libjempbox-java-doc libfontbox-java libfontbox-java-doc Architecture: source all Version: 1:1.8.12-1 Distribution: unstable Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Emmanuel Bourg <ebourg@apache.org> Description: libfontbox-java - Java font library libfontbox-java-doc - Java font library (Documentation) libjempbox-java - XMP Compatible Java Library libjempbox-java-doc - XMP Compatible Java Library (documentation) libpdfbox-java - PDF library for Java libpdfbox-java-doc - PDF library for Java (documentation) Changes: libpdfbox-java (1:1.8.12-1) unstable; urgency=high . * New upstream release - Fixes CVE-2016-2175: XML External Entity vulnerability * Build with maven-debian-helper instead of ant * Removed the non-free 'sRGB Color Space Profile.icm' file from the tarball * Merged the BouncyCastle patches * Standards-Version updated to 3.9.8 (no changes) * Use a secure Vcs-Git URL Checksums-Sha1: ed5bf35dbced1f67b932a7f2abe29f700035b28f 2667 libpdfbox-java_1.8.12-1.dsc 44dd4f05297de72cb24df9401387035c82c5d14d 6540272 libpdfbox-java_1.8.12.orig.tar.xz 610178d50f2d58ac28ba6c4ce7e98a0b8e8a5b32 13108 libpdfbox-java_1.8.12-1.debian.tar.xz 0ec6f2212c6c78be1094209896d53c51c3819145 118322 libfontbox-java-doc_1.8.12-1_all.deb a7673b34c68e2a1973f3f391223b4cb5dc670553 205412 libfontbox-java_1.8.12-1_all.deb 661a62b38eb785dd6e965d8cef6f5bb58fd58d10 61650 libjempbox-java-doc_1.8.12-1_all.deb cab8ce89f2a048b90a30b58cee3a8cc96ce0013e 50572 libjempbox-java_1.8.12-1_all.deb 7008299b760a7d182cf35d3e3cf2e89500a237ea 872206 libpdfbox-java-doc_1.8.12-1_all.deb 7eaa4bda9aef2fc3936dfef38702e2d5beea8ff4 5162182 libpdfbox-java_1.8.12-1_all.deb Checksums-Sha256: 1a926a6f0864c6051b69f3bb6728f978bcf0a660c737617f6cdde5f56f79b571 2667 libpdfbox-java_1.8.12-1.dsc 73db9f29a735b6c44f44a61a8a8fe8f2af2aabbaba8b6df581da55b77c86972e 6540272 libpdfbox-java_1.8.12.orig.tar.xz f453dc934ae864da91984751d2609b08fd3355dbb57ba3e42b7aae2c0518f49d 13108 libpdfbox-java_1.8.12-1.debian.tar.xz 5c03602338d69bca24f41f210c26ccbf7238804bf627f07381718fdbfec217ed 118322 libfontbox-java-doc_1.8.12-1_all.deb e75f4916130317434c0e2070614007cafc7681a59eadfbc443868c0198c179a5 205412 libfontbox-java_1.8.12-1_all.deb ba38fd7b50a4de20843a4ea29dc7f0592d508f54c4478a307976e9c9ba115651 61650 libjempbox-java-doc_1.8.12-1_all.deb 3733c516716458fc24ddc5694435a4843200fc9fcc2f5ce66e2700e73181c83b 50572 libjempbox-java_1.8.12-1_all.deb 1ec6b617c7f158e763be10839946513759aa06b3e1fa4ae85bf0666678d2a119 872206 libpdfbox-java-doc_1.8.12-1_all.deb 97dc45f5f7e307a2fe09b6ec8b168cc6ffe0b806e31a791ec4b67c3306b8ae56 5162182 libpdfbox-java_1.8.12-1_all.deb Files: b4eec161d6d343479f0e71cd2ab130e0 2667 java optional libpdfbox-java_1.8.12-1.dsc 303f34ef491126470bff5de2c834566d 6540272 java optional libpdfbox-java_1.8.12.orig.tar.xz 7f012bbf7a733b466449ae8f5dc3eb76 13108 java optional libpdfbox-java_1.8.12-1.debian.tar.xz cf5bfb73c3c976de7b3a8976862386b4 118322 doc optional libfontbox-java-doc_1.8.12-1_all.deb a19a9dc77d92521e5010670e66fb00fe 205412 java optional libfontbox-java_1.8.12-1_all.deb cd2297974e30fbd0fb84cfc9379b9878 61650 doc optional libjempbox-java-doc_1.8.12-1_all.deb 6d52cde699c3cf6bd2193d681d712ed5 50572 java optional libjempbox-java_1.8.12-1_all.deb 7042a792e81a7f020d08e9c5068cfcf9 872206 doc optional libpdfbox-java-doc_1.8.12-1_all.deb 5123a3deff0122b554747f399f6f30ef 5162182 java optional libpdfbox-java_1.8.12-1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJXTqTKAAoJEPUTxBnkudCs3d4P+wTk8qhHcEGAo8nrpwyze4uv khPWfV/73eU4TJG13AyMcTbe1jAvzCNS86ApNb0ZPKTrCVU/a2li9j+krJA6V9SW Zs/z6VdN9RspwviRca0Ii6jmGsHn51HWAFuXx63Wg5Kuo3jUpd+loJVlIE6IIr3W YQd9xFaORCAdWQnDFYeTrDFLjVQ8LYs6yVrS6Z0DQuyWX8GLdYZS9YaZoP3ZlA+1 lYJQbR6ZYtAJ01FwX0mpo+XJroIrNTX28tEm8a5ZYDr5G9anaGTMFJT5+t6TI0Df HB0F2RbwIYZ6Acs6MAUVHjTOWvSOLydalz+pZuyb0TK2TrirxglltBsbDLQp/U3R S+qxiVR6xbvRGOb027VUnqq5ivzdAluKGcp6IWf+T63DJquNNG7AAlA6Ey+zNAOL 4XuyD0M6JT60mPGzFx8pcWdezKK6Vx/uXfIkTMzENg/YadyPgcU5xyOty4vtfEEV 0YC8mFN1JqxvXl8x19dBddHFpUwK/7dMGe1azBDuB/mToccL5GLH6pgMJkc73jX0 n4/enZdrrYY2JtgquU8yp52SD+3leWLUBJrU93/L6Up+PZGPImxrPrK/ybtXOvy1 ZX9EdLPIVkWu1UmU7ThBCoIEgvSgkvVgMEUsXbnkIN022VrwIaRzmj5q57Nf0nZ4 ssG/n77VkQVC6GuRVRhd =x4WC -----END PGP SIGNATURE-----