-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 30 May 2018 18:59:04 +0200 Source: batik Binary: libbatik-java Architecture: source all Version: 1.8-4+deb9u1 Distribution: stretch-security Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Description: libbatik-java - xml.apache.org SVG Library Closes: 860566 899374 Changes: batik (1.8-4+deb9u1) stretch-security; urgency=high . * Team upload. * Fix CVE-2017-5662: XXE information disclosure. (Closes: #860566) * Fix CVE-2018-8013: information disclosure when deserializing a subclass of AbstractDocument. (Closes: #899374) Checksums-Sha1: 2ab776502c481cc9e2d43acc5b3abf30bb4fcb28 2373 batik_1.8-4+deb9u1.dsc 874c6e71c37f13b706b18e5007f6c48b13183095 7504664 batik_1.8.orig.tar.gz 1144d669a7c2251d1b5de7fc83d71d0037cd65d5 14528 batik_1.8-4+deb9u1.debian.tar.xz dfdd39e26731df20e550231da4d06ebf3fffe108 11593 batik_1.8-4+deb9u1_amd64.buildinfo 35bd8f6bf9309ec6462152f05197eb1091ec2f93 2891780 libbatik-java_1.8-4+deb9u1_all.deb Checksums-Sha256: 0992d7d659d013610f22099fcdbd9ccef6ecd26d6ac07a9d22c2dd04a3d6a3c2 2373 batik_1.8-4+deb9u1.dsc bfd18b0eb3f4ae32655f929e510b630bddb4e00ac3e08af4881027c635eb1624 7504664 batik_1.8.orig.tar.gz c6fdce714d335d731befe02f394541dfc10f1f6307ba95be3c8d70e867f0f1bd 14528 batik_1.8-4+deb9u1.debian.tar.xz abc0b0d9855953078e70e2cdee82d635669e0c9a2fa5b388ce24a1c736d44a9a 11593 batik_1.8-4+deb9u1_amd64.buildinfo 7a6a1c13462c834c3bba4c8a7d589b89f92bea44c9ea43306d098b82eb86cfc9 2891780 libbatik-java_1.8-4+deb9u1_all.deb Files: 7597d60c294a4199b5a24f735fdb3577 2373 java optional batik_1.8-4+deb9u1.dsc 8999291b3cfc8cda4673243d67d697e0 7504664 java optional batik_1.8.orig.tar.gz 0379ade4865b5690ecfdd2a55b5a1c44 14528 java optional batik_1.8-4+deb9u1.debian.tar.xz 56031a1d2d80207cf4813a1763bbfbcc 11593 java optional batik_1.8-4+deb9u1_amd64.buildinfo c1d08aeacd6b7581d47aae3bac948d38 2891780 java optional libbatik-java_1.8-4+deb9u1_all.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlsP4hJfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkMr0P+gLGHZnrCcPBKx7sdL6jsKIi+IeIITu8uBK+ JrT78DEVznf8YZOw3mw41GaFo/bLHoC2epxgoXERSgBEYxEVA4EXmAv4ENtOhlJ8 pH0umSeW+XtCmgayPgw9sh5AsGj2O+xBT5UMstJJrJ9phrsNpQlEcpMNy86E0vib jibsBNL72qt3pu79lqmYSFioTcJQUxXB4q5f+bTYYVk6CEv61UXwyScirtV1kPtm h8ErSZaR/jy+/0KX1X32j+ad4Bl3D0cgp/x4uY7w4CQA74pbFQDDCRJpS/K43dGX EFdpXR2eiPvRURdt7F4Ysfs1HkmUCWyw/UHwPWf6U4qprAb0d9Xx/rvTaZz6MThb /6ZhCABqIR03TUxJMUpMcXQzpEr/7KeLA4rSYjPj39Zm1eGVyHlqnXb2q7mOzDPA pd8yt+P+/shZzx+Bg9rMvqbQYelb1tldT5PpPhriEKGJrknHxvlEm16nYX/PXUjX jXE9YGsLwMWlMHKul9XUhnicUN7IWlXWgX6TEqzzC18UE+X+1Ag4mfjHLXnHSutj cBOcgNEzsvysIVfcazzAoX9jqiF64O1F46RoD/SfYqueLe3oVCA817wRoz7Il2+5 7wkLgHk2v2iZ/n3/XgYluwJmGD3yNl3xDVgraL6ULOaOjHbUGt6ixYuPcC5GJzMV tzjvLAtw =KOGi -----END PGP SIGNATURE-----