Debian Package Tracker
Register | Log in
Subscribe

libcommons-lang3-java

Apache Commons Lang utility classes

Choose email to subscribe with

general
  • source: libcommons-lang3-java (main)
  • version: 3.17.0-1
  • maintainer: Debian Java Maintainers (archive) (DMD)
  • uploaders: Emmanuel Bourg [DMD]
  • arch: all
  • std-ver: 4.7.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 3.11-1
  • stable: 3.12.0-2
  • testing: 3.17.0-1
  • unstable: 3.17.0-1
versioned links
  • 3.11-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.12.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.17.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libcommons-lang3-java
action needed
A new upstream version is available: 3.18.0 high
A new upstream version 3.18.0 is available, you should consider packaging it.
Created: 2025-07-12 Last update: 2025-07-28 13:02
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2025-48924: Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Created: 2025-07-11 Last update: 2025-07-16 14:32
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2025-48924: Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Created: 2025-07-11 Last update: 2025-07-16 14:32
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2025-48924: Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.
Created: 2025-07-11 Last update: 2025-07-16 14:32
1 low-priority security issue in bookworm low

There is 1 open security issue in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2025-48924: (needs triaging) Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0. The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a StackOverflowError could cause an application to stop. Users are recommended to upgrade to version 3.18.0, which fixes the issue.

You can find information about how to handle this issue in the security team's documentation.

Created: 2025-07-11 Last update: 2025-07-16 14:32
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.2 instead of 4.7.0).
Created: 2025-02-21 Last update: 2025-02-27 13:25
news
[rss feed]
  • [2024-10-31] libcommons-lang3-java 3.17.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-10-25] Accepted libcommons-lang3-java 3.17.0-1 (source) into unstable (Emmanuel Bourg)
  • [2024-01-11] libcommons-lang3-java 3.14.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-05] Accepted libcommons-lang3-java 3.14.0-1 (source) into unstable (Emmanuel Bourg)
  • [2023-11-13] libcommons-lang3-java 3.13.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-11-08] Accepted libcommons-lang3-java 3.13.0-1 (source) into unstable (Andrius Merkys)
  • [2022-05-09] libcommons-lang3-java 3.12.0-2 MIGRATED to testing (Debian testing watch)
  • [2022-05-03] Accepted libcommons-lang3-java 3.12.0-2 (source) into unstable (Emmanuel Bourg)
  • [2022-05-03] Accepted libcommons-lang3-java 3.12.0-1 (source) into unstable (Emmanuel Bourg)
  • [2020-08-02] libcommons-lang3-java 3.11-1 MIGRATED to testing (Debian testing watch)
  • [2020-07-27] Accepted libcommons-lang3-java 3.11-1 (source) into unstable (Andrius Merkys)
  • [2018-12-01] libcommons-lang3-java 3.8-2 MIGRATED to testing (Debian testing watch)
  • [2018-11-26] Accepted libcommons-lang3-java 3.8-2 (source) into unstable (Emmanuel Bourg)
  • [2018-09-25] libcommons-lang3-java 3.8-1 MIGRATED to testing (Debian testing watch)
  • [2018-09-19] Accepted libcommons-lang3-java 3.8-1 (source) into unstable (Emmanuel Bourg)
  • [2018-05-09] libcommons-lang3-java 3.7-1 MIGRATED to testing (Debian testing watch)
  • [2018-05-04] Accepted libcommons-lang3-java 3.7-1 (source all) into unstable (Emmanuel Bourg)
  • [2018-04-21] libcommons-lang3-java 3.5-2 MIGRATED to testing (Debian testing watch)
  • [2018-04-16] Accepted libcommons-lang3-java 3.5-2 (source) into unstable (Markus Koschany)
  • [2016-10-26] libcommons-lang3-java 3.5-1 MIGRATED to testing (Debian testing watch)
  • [2016-10-20] Accepted libcommons-lang3-java 3.5-1 (source all) into unstable (Emmanuel Bourg)
  • [2016-08-08] libcommons-lang3-java 3.4-2 MIGRATED to testing (Debian testing watch)
  • [2016-08-01] Accepted libcommons-lang3-java 3.4-2 (source all) into unstable (Emmanuel Bourg)
  • [2015-05-03] libcommons-lang3-java 3.4-1 MIGRATED to testing (Britney)
  • [2015-04-27] Accepted libcommons-lang3-java 3.4-1 (source all) into unstable (Emmanuel Bourg)
  • [2014-04-22] libcommons-lang3-java 3.3.2-1 MIGRATED to testing (Debian testing watch)
  • [2014-04-17] Accepted libcommons-lang3-java 3.3.2-1 (source all) (Emmanuel Bourg)
  • [2014-03-25] libcommons-lang3-java 3.3.1-1 MIGRATED to testing (Debian testing watch)
  • [2014-03-19] Accepted libcommons-lang3-java 3.3.1-1 (source all) (Emmanuel Bourg)
  • [2014-03-14] libcommons-lang3-java 3.3-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.17.0-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing