[ubuntu/plucky-proposed] libspring-java 4.3.30-2ubuntu1 (Accepted)
Hlib Korzhynskyy
hlib.korzhynskyy at canonical.com
Mon Dec 16 15:43:15 UTC 2024
libspring-java (4.3.30-2ubuntu1) plucky; urgency=medium
* SECURITY UPDATE: Remote code execution through PropertyDescriptor.
- debian/patches/CVE-2022-22965.patch: Don't allow binding non-class
properties name variants in .../beans/CachedIntrospectionResults.java.
- CVE-2022-22965
Date: Thu, 12 Dec 2024 16:08:29 -0330
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/libspring-java/4.3.30-2ubuntu1
-------------- next part --------------
Format: 1.8
Date: Thu, 12 Dec 2024 16:08:29 -0330
Source: libspring-java
Built-For-Profiles: noudeb
Architecture: source
Version: 4.3.30-2ubuntu1
Distribution: plucky
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
Changes:
libspring-java (4.3.30-2ubuntu1) plucky; urgency=medium
.
* SECURITY UPDATE: Remote code execution through PropertyDescriptor.
- debian/patches/CVE-2022-22965.patch: Don't allow binding non-class
properties name variants in .../beans/CachedIntrospectionResults.java.
- CVE-2022-22965
Checksums-Sha1:
edc85290609a911d9fa75de537ae6c5432293b9d 5343 libspring-java_4.3.30-2ubuntu1.dsc
114d08c08ae2e6bd78f326fdf54cdce80464a6be 22836 libspring-java_4.3.30-2ubuntu1.debian.tar.xz
8341b1fad9ffaede0bfb2e31c0db328566cbe033 15446 libspring-java_4.3.30-2ubuntu1_source.buildinfo
Checksums-Sha256:
fd13094912433c82de8f91d09fbe4f920a121c43a7b3fa4288fb4cd4fbb3c72c 5343 libspring-java_4.3.30-2ubuntu1.dsc
ead88849c05b97b620b1103f36d3aa576e5a65bf2d3de87f20402af19fc6470f 22836 libspring-java_4.3.30-2ubuntu1.debian.tar.xz
602fc5178169cd12e6346ca46a54f7ee363136ba93e1438094a9d17e1822baa6 15446 libspring-java_4.3.30-2ubuntu1_source.buildinfo
Files:
84e4e6b5149e3d1e057af90d258faa4e 5343 java optional libspring-java_4.3.30-2ubuntu1.dsc
adfe5a26e78d9fe3c619596bcfa2ec17 22836 java optional libspring-java_4.3.30-2ubuntu1.debian.tar.xz
3bc9698846ff584eb8a97aad329d73d8 15446 java optional libspring-java_4.3.30-2ubuntu1_source.buildinfo
Original-Maintainer: Debian Java Maintainers <pkg-java-maintainers at lists.alioth.debian.org>
More information about the plucky-changes
mailing list