Originally uploaded to
debian sid in
Primary Archive for Debian GNU/Linux
Changelog
libhibernate3-java (3.6.10.Final-11) unstable; urgency=medium
* Team upload.
* Fix CVE-2020-25638:
A flaw was found in hibernate-core. A SQL injection in the implementation
of the JPA Criteria API can permit unsanitized literals when a literal is
used in the SQL comments of the query. This flaw could allow an attacker to
access unauthorized information or possibly conduct further attacks. The
highest threat from this vulnerability is to data confidentiality and
integrity.
* Declare compliance with Debian Policy 4.5.1.
* Switch to debhelper-compat = 13.
-- Markus Koschany <email address hidden> Sun, 03 Jan 2021 16:45:50 +0100