jackrabbit 2.3.6-1+deb8u1build0.15.04.1 source package in Ubuntu

Changelog

jackrabbit (2.3.6-1+deb8u1build0.15.04.1) vivid-security; urgency=medium

  * fake sync from Debian

jackrabbit (2.3.6-1+deb8u1) jessie-security; urgency=medium

  * Team upload.
  * Add CVE-2015-1833.patch.
    Fix XXE/XEE vulnerability of the Jackrabbit WebDAV bundle.
    When processing a WebDAV request body containing XML, the XML parser can be
    instructed to read content from network resources accessible to the host,
    identified by URI schemes such as "http(s)" or "file". Depending on the
    WebDAV request, this can not only be used to trigger internal network
    requests, but might also be used to insert said content into the request,
    potentially exposing it to the attacker and others. (Closes: #787316)

 -- Steve Beattie <email address hidden>  Wed, 01 Jul 2015 09:33:10 -0700

Upload details

Uploaded by:
Steve Beattie
Uploaded to:
Vivid
Original maintainer:
Debian Java Maintainers
Architectures:
all
Section:
java
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Vivid: [FULLYBUILT] amd64

Downloads

File Size SHA-256 Checksum
jackrabbit_2.3.6.orig.tar.gz 3.8 MiB 1e91f2e985899464d51e5b89170efbb9aa844c88fdee4e1d8b40ef6aba1faf99
jackrabbit_2.3.6-1+deb8u1build0.15.04.1.debian.tar.xz 8.8 KiB 685fa7a14004d51b43bdc926697099163c06fbdbd5ed7f0d9feecbd50f8c833c
jackrabbit_2.3.6-1+deb8u1build0.15.04.1.dsc 2.1 KiB ac8d9389063fb754bb0ddc7db14fc945eb57a85edff8a307fe07b68336bafae7

View changes file

Binary packages built by this source

libjackrabbit-java: No summary available for libjackrabbit-java in ubuntu vivid.

No description available for libjackrabbit-java in ubuntu vivid.