[ubuntu/kinetic-proposed] maven 3.6.3-5ubuntu1 (Accepted)
Nishit Majithia
nishit.majithia at canonical.com
Thu Aug 18 12:19:15 UTC 2022
maven (3.6.3-5ubuntu1) kinetic; urgency=medium
* SECURITY UPDATE: Insufficient Verification of Data Authenticity
- debian/patches/CVE-2021-26291.patch: Block HTTP repositories by default.
- CVE-2021-26291
Date: Tue, 16 Aug 2022 18:24:18 +0530
Changed-By: Nishit Majithia <nishit.majithia at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Alex Murray <alex.murray at canonical.com>
https://launchpad.net/ubuntu/+source/maven/3.6.3-5ubuntu1
-------------- next part --------------
Format: 1.8
Date: Tue, 16 Aug 2022 18:24:18 +0530
Source: maven
Built-For-Profiles: noudeb
Architecture: source
Version: 3.6.3-5ubuntu1
Distribution: kinetic
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Nishit Majithia <nishit.majithia at canonical.com>
Changes:
maven (3.6.3-5ubuntu1) kinetic; urgency=medium
.
* SECURITY UPDATE: Insufficient Verification of Data Authenticity
- debian/patches/CVE-2021-26291.patch: Block HTTP repositories by default.
- CVE-2021-26291
Checksums-Sha1:
7a6203ee181fc7ba9226af5632c319c22b1ee7a4 2672 maven_3.6.3-5ubuntu1.dsc
6d34a46c57288a806b39df34d3218ae755613923 16480 maven_3.6.3-5ubuntu1.debian.tar.xz
90a4dc4d884805e0943dde01b50b9dd9005de0b9 13516 maven_3.6.3-5ubuntu1_source.buildinfo
Checksums-Sha256:
86fcf4b9af8262bbcfd8f9391d88d8108959f041d2bc18d230a90e25798f6b02 2672 maven_3.6.3-5ubuntu1.dsc
bea16773d0ce8cd289eb8af8ddbb7f291eb977ea491087506b884c85b7456497 16480 maven_3.6.3-5ubuntu1.debian.tar.xz
de88960889e169da6eabf6b2a730be1f7e9fdb3db92179bf81ee80ce710c1f42 13516 maven_3.6.3-5ubuntu1_source.buildinfo
Files:
0fc2dbf32ad8c086b9adb6398f2a7246 2672 java optional maven_3.6.3-5ubuntu1.dsc
46a10cfc5c4b2c4a28c79fcbaa7722d4 16480 java optional maven_3.6.3-5ubuntu1.debian.tar.xz
bf06843d689a6d6d29f194de5356f200 13516 java optional maven_3.6.3-5ubuntu1_source.buildinfo
Original-Maintainer: Debian Java Maintainers <pkg-java-maintainers at lists.alioth.debian.org>
More information about the kinetic-changes
mailing list