[ubuntu/kinetic-proposed] maven 3.6.3-5ubuntu1 (Accepted)

Nishit Majithia nishit.majithia at canonical.com
Thu Aug 18 12:19:15 UTC 2022


maven (3.6.3-5ubuntu1) kinetic; urgency=medium

  * SECURITY UPDATE: Insufficient Verification of Data Authenticity
    - debian/patches/CVE-2021-26291.patch: Block HTTP repositories by default.
    - CVE-2021-26291

Date: Tue, 16 Aug 2022 18:24:18 +0530
Changed-By: Nishit Majithia <nishit.majithia at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Alex Murray <alex.murray at canonical.com>
https://launchpad.net/ubuntu/+source/maven/3.6.3-5ubuntu1
-------------- next part --------------
Format: 1.8
Date: Tue, 16 Aug 2022 18:24:18 +0530
Source: maven
Built-For-Profiles: noudeb
Architecture: source
Version: 3.6.3-5ubuntu1
Distribution: kinetic
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Nishit Majithia <nishit.majithia at canonical.com>
Changes:
 maven (3.6.3-5ubuntu1) kinetic; urgency=medium
 .
   * SECURITY UPDATE: Insufficient Verification of Data Authenticity
     - debian/patches/CVE-2021-26291.patch: Block HTTP repositories by default.
     - CVE-2021-26291
Checksums-Sha1:
 7a6203ee181fc7ba9226af5632c319c22b1ee7a4 2672 maven_3.6.3-5ubuntu1.dsc
 6d34a46c57288a806b39df34d3218ae755613923 16480 maven_3.6.3-5ubuntu1.debian.tar.xz
 90a4dc4d884805e0943dde01b50b9dd9005de0b9 13516 maven_3.6.3-5ubuntu1_source.buildinfo
Checksums-Sha256:
 86fcf4b9af8262bbcfd8f9391d88d8108959f041d2bc18d230a90e25798f6b02 2672 maven_3.6.3-5ubuntu1.dsc
 bea16773d0ce8cd289eb8af8ddbb7f291eb977ea491087506b884c85b7456497 16480 maven_3.6.3-5ubuntu1.debian.tar.xz
 de88960889e169da6eabf6b2a730be1f7e9fdb3db92179bf81ee80ce710c1f42 13516 maven_3.6.3-5ubuntu1_source.buildinfo
Files:
 0fc2dbf32ad8c086b9adb6398f2a7246 2672 java optional maven_3.6.3-5ubuntu1.dsc
 46a10cfc5c4b2c4a28c79fcbaa7722d4 16480 java optional maven_3.6.3-5ubuntu1.debian.tar.xz
 bf06843d689a6d6d29f194de5356f200 13516 java optional maven_3.6.3-5ubuntu1_source.buildinfo
Original-Maintainer: Debian Java Maintainers <pkg-java-maintainers at lists.alioth.debian.org>


More information about the kinetic-changes mailing list