Publishing details

Changelog

fop (1:1.1.dfsg-2ubuntu1.1) trusty-security; urgency=medium

  * SECURITY UPDATE: SSRF through external DTD resolution
    - debian/patches/CVE-2017-5661.patch: disable external DTD resolution
      in src/java/org/apache/fop/cli/InputHandler.java,
      src/java/org/apache/fop/servlet/FopServlet.java.
    - Thanks to Debian for the patch backport.
    - CVE-2017-5661

 -- Marc Deslauriers <email address hidden>  Thu, 04 May 2017 12:56:32 -0400

Available diffs

Builds

Built packages

Package files