-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Tue, 18 Apr 2017 14:30:00 +0200 Source: apache-log4j2 Binary: liblog4j2-java liblog4j2-java-doc Architecture: source Version: 2.7-2 Distribution: unstable Urgency: medium Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Emmanuel Bourg <ebourg@apache.org> Description: liblog4j2-java - Apache Log4j - Logging Framework for Java liblog4j2-java-doc - Documentation for Apache Log4j 2 Closes: 860489 Changes: apache-log4j2 (2.7-2) unstable; urgency=medium . * Team upload. * Fixed CVE-2017-5645: When using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code (Closes: #860489) Checksums-Sha1: 876caec08e0dd244c2f659a5929b77003362360e 2886 apache-log4j2_2.7-2.dsc e0d5b663d2238cc59c0d7a9e1efaea4aaa4825b9 8440 apache-log4j2_2.7-2.debian.tar.xz 9c1f873b9743e386c1829f3f62d062a943fdac2e 14653 apache-log4j2_2.7-2_source.buildinfo Checksums-Sha256: dfa96b6d21c6c4d698640d2ba5e918306da215cdabf0dbc1b3c65686379e0d26 2886 apache-log4j2_2.7-2.dsc 68fef80f76648b9835ce7990a9238d86cff99af722e2d28a5528ddced3f07c71 8440 apache-log4j2_2.7-2.debian.tar.xz 33ce7f2156f8ec4ee5c9aebf0b54296343f772cd2aad6937eb550e47351e9b60 14653 apache-log4j2_2.7-2_source.buildinfo Files: ee59e794d0c7205f735742c58a83dd76 2886 java optional apache-log4j2_2.7-2.dsc c405df976dea2058f26495918141df8b 8440 java optional apache-log4j2_2.7-2.debian.tar.xz 978daedb3c643314ebdb5030a63f5d5c 14653 java optional apache-log4j2_2.7-2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJGBAEBCAAwFiEEuM5N4hCA3PkD4WxA9RPEGeS50KwFAlj2Cp8SHGVib3VyZ0Bh cGFjaGUub3JnAAoJEPUTxBnkudCsOzIP+wSzPlVMZO9SrnlPh9rlRL/p3DLYlAXB Fh0LbqaN4IFur1LyzIUGfWFLXNdHQW/CSwfGql1hUC07MohRjAdznUQe0BQzAb2W 8KYUvabxnpkRoLaFJ+4Y1nC8X/fXTqp+2285oFWwmshp5nbQFynIgB+i6MxWab4m dPuGD1bEtNqoA9XcVl3mKyHwHwNk+T7mpmTjRNyZ2HSCAu3s4fRHn/C8C8vs6k0c iQ94coHJ18fMF1O1bKP9ShQt2W+eesmUI7AnaOVb1CE+UpziIGPRYz9WxAWLpSg+ zDY2eh0FEocPHZfuJPkngWGfjS6fjNsYx/HgEWJw2kZc8GQdk257VR++0cbPRzbc rQJKizXC34E7lWu8U9jKVCG8SBOqbcITMUlgNut2a/qdAgELl4O/Nv5vTE67mF81 2uJ7FSRPShDQxlo9PRz+oJ7pRRKFJAULnYZBrAjsyqtWcrDI+/MpEhit21GX3Hs3 OiZS2wdHXyfxmzjk/AiDdkc669HHu0uWcGTVrZYY81hxBP1Jpn9cbXhCQ1CDW07b TODQE1RF81fJtauNpp2yE3wqG9TlywY4SK6255PVIZDeUM+EbuTXV3YOgL3P1Lo7 sFCs0+meoqQXyPGjfiXo15qdj9bSF0QEiRogidtqYhVDIdNZ6GimVyVa1D6r3Smp wHsiqOUV8l7u =BcgQ -----END PGP SIGNATURE-----