Debian Package Tracker
Register | Log in
Subscribe

batik

xml.apache.org SVG Library

Choose email to subscribe with

general
  • source: batik (source, libs)
  • version: 1.9-3
  • maintainer: Debian Java Maintainers (archive) [DMD]
  • uploaders: Vincent Fourmond [DMD] – Onkar Shinde [DMD] – Wolfgang Baer [DMD]
  • arch: all
  • std-ver: 4.1.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.7+dfsg-3+deb7u1
  • o-o-sec: 1.7+dfsg-3+deb7u2
  • oldstable: 1.7+dfsg-5
  • stable: 1.8-4
  • testing: 1.9-3
  • unstable: 1.9-3
versioned links
  • 1.7+dfsg-3+deb7u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.7+dfsg-3+deb7u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.7+dfsg-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.8-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.9-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libbatik-java
action needed
lintian reports 1 error and 4 warnings
high
Lintian reports 1 error and 4 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2017-09-14 Last update: 2017-12-29 07:31
1 bug tagged patch in the BTS
normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2017-11-21 Last update: 2018-01-04 07:31
10 new commit since last upload, time to release an update?
normal
vcswatch reports that this package seems to have new commits in its VCS. You should consider updating the debian/changelog and uploading this new version into the archive.

Created: 2017-12-03 Last update: 2017-12-03 14:13
1 ignored security issue in stretch
low
There is 1 open security issue in stretch.
1 issue skipped by the security teams:
  • CVE-2017-5662: In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
Please fix it.
Created: 2017-04-18 Last update: 2017-12-30 19:43
1 ignored security issue in jessie
low
There is 1 open security issue in jessie.
1 issue skipped by the security teams:
  • CVE-2017-5662: In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
Please fix it.
Created: 2017-04-18 Last update: 2017-12-30 19:43
news
[rss feed]
  • [2017-10-08] batik 1.9-3 MIGRATED to testing (Debian testing watch)
  • [2017-10-02] Accepted batik 1.9-3 (source) into unstable (Emmanuel Bourg)
  • [2017-09-18] batik 1.9-2 MIGRATED to testing (Debian testing watch)
  • [2017-09-13] Accepted batik 1.9-2 (source) into unstable (Christopher Hoskin)
  • [2017-09-09] batik 1.9-1 MIGRATED to testing (Debian testing watch)
  • [2017-09-04] Accepted batik 1.9-1 (source) into unstable (Christopher Hoskin)
  • [2017-04-29] Accepted batik 1.7+dfsg-3+deb7u2 (source all) into oldstable (Antoine Beaupré)
  • [2016-10-12] batik 1.8-4 MIGRATED to testing (Debian testing watch)
  • [2016-10-07] Accepted batik 1.8-4 (source) into unstable (Mathieu Malaterre)
  • [2015-10-26] batik 1.8-3 MIGRATED to testing (Britney)
  • [2015-09-13] Accepted batik 1.8-3 (source all) into unstable (Mathieu Malaterre)
  • [2015-07-16] Accepted batik 1.8-2 (source all) into experimental (Mathieu Malaterre)
  • [2015-07-12] Accepted batik 1.8-1 (source all) into experimental (Mathieu Malaterre)
  • [2015-03-29] Accepted batik 1.7+dfsg-3+deb7u1 (source all) into proposed-updates->stable-new, proposed-updates (tony mancill)
  • [2015-03-27] Accepted batik 1.7-6+deb6u1 (source all) into squeeze-lts (Thorsten Alteholz)
  • [2015-03-27] batik 1.7+dfsg-5 MIGRATED to testing (Britney)
  • [2015-03-21] Accepted batik 1.7+dfsg-5 (source all) into unstable (tony mancill)
  • [2013-10-27] batik 1.7+dfsg-4 MIGRATED to testing (Debian testing watch)
  • [2013-10-17] Accepted batik 1.7+dfsg-4 (source all) (Markus Koschany) (signed by: tony mancill)
  • [2012-07-04] batik 1.7+dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2012-06-23] Accepted batik 1.7+dfsg-3 (source all) (Niels Thykier)
  • [2012-06-19] Accepted batik 1.7+dfsg-2 (source all) (Niels Thykier)
  • [2012-03-23] batik 1.7+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2012-03-12] Accepted batik 1.7+dfsg-1 (source all) (Vincent Fourmond)
  • [2011-10-10] batik 1.7-8 MIGRATED to testing (Debian testing watch)
  • [2011-09-29] Accepted batik 1.7-8 (source all) (Vincent Fourmond)
  • [2011-02-06] batik 1.7-7 MIGRATED to testing (Debian testing watch)
  • [2010-11-25] Accepted batik 1.7-7 (source all) (Vincent Fourmond)
  • [2010-03-04] batik 1.7-6 MIGRATED to testing (Debian testing watch)
  • [2010-02-21] Accepted batik 1.7-6 (source all) (Gabriele Giacone) (signed by: Torsten Werner)
  • 1
  • 2
bugs [bug history graph]
  • all: 3
  • RC: 1
  • I&N: 0
  • M&W: 2
  • F&P: 0
links
  • homepage
  • lintian (1, 4)
  • buildd: logs, clang, reproducibility
  • popcon
  • browse source code
  • edit tags
  • security tracker
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.9-3
  • 3 bugs

Debian Package Tracker — Copyright 2013-2016 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Git Repository — How to contribute