-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 24 Apr 2017 13:41:45 +0200 Source: logback Binary: liblogback-java liblogback-java-doc Architecture: source all Version: 1:1.1.2-1+deb8u1 Distribution: jessie Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: liblogback-java - flexible logging library for Java liblogback-java-doc - flexible logging library for Java - documentation Closes: 857343 Changes: logback (1:1.1.2-1+deb8u1) jessie; urgency=high . * Team upload. * Fix CVE-2017-5929: It was discovered that logback, a flexible logging library for Java, would deserialize data from untrusted sockets. This issue has been resolved by adding a whitelist to use only trusted classes. (Closes: #857343) Checksums-Sha1: 279a0764fb1ff52d1aaba3925722adccee03236b 2270 logback_1.1.2-1+deb8u1.dsc 951e6cd1c497d14fb10ebf518937928232cdc830 11560 logback_1.1.2-1+deb8u1.debian.tar.xz daed26934cf922a190b4c317841b69cf985a2d14 624718 liblogback-java_1.1.2-1+deb8u1_all.deb 025cebc4db3445261cb9f87a5a62f832e9cdf138 1778332 liblogback-java-doc_1.1.2-1+deb8u1_all.deb Checksums-Sha256: 103395aa6dbb290dd74454254fd83e04f2c02c4612d2f83c98da692b64ee240e 2270 logback_1.1.2-1+deb8u1.dsc 502d128e960a611893292515072edeb33bec82811c526251d29655a499a15e77 11560 logback_1.1.2-1+deb8u1.debian.tar.xz fa847a1bf2f3e3e28e9196376ea21494164a8cc2c1b350cbc47aab740a2c89b6 624718 liblogback-java_1.1.2-1+deb8u1_all.deb 6c7b00e07633a53dd6cb5775c0968347583388b81b1014398ea8b140ba76cb3a 1778332 liblogback-java-doc_1.1.2-1+deb8u1_all.deb Files: b507b7bdd6ac787dd21281e1abd4a6e2 2270 java optional logback_1.1.2-1+deb8u1.dsc 0c376c4b6f715d0351c1f3168ac1792c 11560 java optional logback_1.1.2-1+deb8u1.debian.tar.xz 91fae7f0d03b6fe14e15164c97d9537f 624718 java optional liblogback-java_1.1.2-1+deb8u1_all.deb 7c5b86df31d22cd6abdf47c71de76f75 1778332 doc optional liblogback-java-doc_1.1.2-1+deb8u1_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQJ8BAEBCgBmBQJY/eduXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRBQ0YzRDA4OEVGMzJFREVGNkExQTgzNUZE OUFEMTRCOTUxM0I1MUU0AAoJENmtFLlRO1Hks7MQAKh4Qgn7VcUn9rbvY4sRkbec DfL+H6kngUwq+C1lW/RUq9jxv6kPxBOS0KcOwbDNwKlI0aHddCYbCBypJJSV2t3u h+WV/T7r2dvJCQB2/0ZUxzBTMLaWRzyWZZcS6Afj3yyNKlO7ms7hA5ikB3Md73fx NNHbH11tzuUxdGaPgwhaqCrQd1vsmaWcbAvjgdHRh8ColnauixoR3dpdMPADE44E 5cq+iQLn86lkw29Zuws/sKZ1Lh+bEqAT7YmEsI75aUAgOivNkNJYTeBowyAVnvPk lpO4rfNdMiUsCokbWRtytNJ8b24H2l59tnws4xF1bEC+HpJ2+/MlPGjPJBguvx0A /DnCzqArOQ8j03HNc3RdwtD5FqwlSPWy/nwxuS7Xwkpmbj2BHXZx+mez6TVSee1h r9UVwIlA1Z0LWVGN1/wXQleiuP6Xn+WmTpwMk4mCBLJ+1+eSW3rm7Lf7iFVOzrxY eBZc2nqupqA8OyNtoaj+W6D8/AE4M1Dy6sz1DHoK7Jq+Rl5Lfx8hPY2vWJaOcFJC uLupIBSU3BqldGxxmQ9oYqMHw65+PVPAprLjlo/GCpdy1/TpEwv45gSJvV7d1RXI NJQNy62AID5AvLL9yqBTVqoFl+QfMde3KVd2abEjRV5Ismm0iYlljOM01wPkGHWq D+zJf6X5D0PWH/64FkxW =Eb+2 -----END PGP SIGNATURE-----