libcommons-compress-java 1.18-1 source package in Ubuntu
Changelog
libcommons-compress-java (1.18-1) unstable; urgency=medium * Team upload. * New upstream version 1.18. - Fix CVE-2018-11771. When reading a specially crafted ZIP archive, the read method of Apache Commons Compress ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.InputStreamReader this can lead to an infinite stream, which can be used to mount a denial of service attack against services that use Compress' zip package. Thanks to Salvatore Bonaccorso for the report. (Closes: #906301) * Declare compliance with Debian Policy 4.2.0. -- Markus Koschany <email address hidden> Wed, 22 Aug 2018 21:43:55 +0200
Upload details
- Uploaded by:
- Debian Java Maintainers
- Uploaded to:
- Sid
- Original maintainer:
- Debian Java Maintainers
- Architectures:
- all
- Section:
- java
- Urgency:
- Medium Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
libcommons-compress-java_1.18-1.dsc | 2.5 KiB | 1db8cba1436736d2d6b8ce36d46090169fe5343916072cb1483187778fac2210 |
libcommons-compress-java_1.18.orig.tar.xz | 8.6 MiB | 41dff7f5877a3d4d6a9848db3cac1cc7b527cddd1ed50ae258e6ee2b6090a157 |
libcommons-compress-java_1.18-1.debian.tar.xz | 5.7 KiB | d5933da5f42a8e1dde1e70b9ca79c4c6a03fef247736219cd37b11e3881c2aea |
Available diffs
- diff from 1.17-1 to 1.18-1 (19.0 KiB)
No changes file available.
Binary packages built by this source
- libcommons-compress-java: No summary available for libcommons-compress-java in ubuntu cosmic.
No description available for libcommons-
compress- java in ubuntu cosmic.