jackrabbit 2.3.6-1+deb8u1build0.15.04.1 source package in Ubuntu
Changelog
jackrabbit (2.3.6-1+deb8u1build0.15.04.1) vivid-security; urgency=medium * fake sync from Debian jackrabbit (2.3.6-1+deb8u1) jessie-security; urgency=medium * Team upload. * Add CVE-2015-1833.patch. Fix XXE/XEE vulnerability of the Jackrabbit WebDAV bundle. When processing a WebDAV request body containing XML, the XML parser can be instructed to read content from network resources accessible to the host, identified by URI schemes such as "http(s)" or "file". Depending on the WebDAV request, this can not only be used to trigger internal network requests, but might also be used to insert said content into the request, potentially exposing it to the attacker and others. (Closes: #787316) -- Steve Beattie <email address hidden> Wed, 01 Jul 2015 09:33:10 -0700
Upload details
- Uploaded by:
- Steve Beattie
- Uploaded to:
- Vivid
- Original maintainer:
- Debian Java Maintainers
- Architectures:
- all
- Section:
- java
- Urgency:
- Medium Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
jackrabbit_2.3.6.orig.tar.gz | 3.8 MiB | 1e91f2e985899464d51e5b89170efbb9aa844c88fdee4e1d8b40ef6aba1faf99 |
jackrabbit_2.3.6-1+deb8u1build0.15.04.1.debian.tar.xz | 8.8 KiB | 685fa7a14004d51b43bdc926697099163c06fbdbd5ed7f0d9feecbd50f8c833c |
jackrabbit_2.3.6-1+deb8u1build0.15.04.1.dsc | 2.1 KiB | ac8d9389063fb754bb0ddc7db14fc945eb57a85edff8a307fe07b68336bafae7 |
Available diffs
Binary packages built by this source
- libjackrabbit-java: No summary available for libjackrabbit-java in ubuntu vivid.
No description available for libjackrabbit-java in ubuntu vivid.