-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 04 Aug 2021 13:31:34 +0200 Source: xmlgraphics-commons Binary: libxmlgraphics-commons-java libxmlgraphics-commons-java-doc Architecture: all Version: 2.3-1+deb10u1 Distribution: buster Urgency: medium Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Markus Koschany Description: libxmlgraphics-commons-java - Reusable components used by Batik and FOP libxmlgraphics-commons-java-doc - Reusable components used by Batik and FOP (documentation) Closes: 984949 Changes: xmlgraphics-commons (2.3-1+deb10u1) buster; urgency=medium . * Team upload. * Fix CVE-2020-11988: Apache XmlGraphics Commons is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. (Closes: #984949) Checksums-Sha1: 2892ad4acb5553f0ff00088b492efd9fe376cff0 691108 libxmlgraphics-commons-java-doc_2.3-1+deb10u1_all.deb 2246255f229dcfc0b536481165675856d9032bbc 616644 libxmlgraphics-commons-java_2.3-1+deb10u1_all.deb fdfc570803ea86304f4821034a1d6c15d615142e 13768 xmlgraphics-commons_2.3-1+deb10u1_all-buildd.buildinfo Checksums-Sha256: ad160ced2432798e53d168f0446bdd776c56eb31f7850e11fcd1ceef643e6305 691108 libxmlgraphics-commons-java-doc_2.3-1+deb10u1_all.deb 450355aceb2adb3eb7a6d5f326fd533e9ac9bfbcd0ebbfe3e1b7b8892561b7c2 616644 libxmlgraphics-commons-java_2.3-1+deb10u1_all.deb 9f8735b533e10d61739edf821dea74a1ce703b0ada102e3fbb830db76537671d 13768 xmlgraphics-commons_2.3-1+deb10u1_all-buildd.buildinfo Files: 9a2f2cf488347d6a28a7912d9f457616 691108 doc optional libxmlgraphics-commons-java-doc_2.3-1+deb10u1_all.deb 555df07941ca7784a0d82010c9eb426d 616644 java optional libxmlgraphics-commons-java_2.3-1+deb10u1_all.deb d1f6619f499488db93a3ce207772378f 13768 java optional xmlgraphics-commons_2.3-1+deb10u1_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEqQcRQHTGP4qt3opGks26TWZ8cfMFAmEO7eMACgkQks26TWZ8 cfOqHBAAiE7c0kfzv6hSbu7eRPED+yM1uovH+AqVYdqyfUgfXaB7PwY/o8eV+dvU isGZmh3j0PaE+//TZBYL0CNr4vwoAwkgdeGzVHZQTTHCSUC8HfYCKvh8MX6VdoLu bmtHOCRcscrlprh9maHDKQgxcCzDplJpD+wNz70epBsJNHHcckcBcbeB/fFdXqZa 2LbZ/AZ5WTp31hJZs9EVolhbpZBi3QBwt71vlSASmOcqD51MP9OKfk1U/DT9eZen 6YGCKYBEW9EFnUPB6QIpPOqu932jllIlRKCx4snWQl9b7ymGXe6FOQS40BlhNZCf YvLc8DCBcfriGcTia4N2JbJJnrt7dM/3zgLhbbNNcG+DdB1PwyFycS11BhLqS32Q rFCpK+IuaXwVBLjXZNfCQzTkkYaXzRb/AEt7aVuBza5w0YCmbyadoXAw21gB3fYk 9lr77Z42STeqgPXKTqOqIM9U019cbAC3CC0TtxFsb6gkDz+2nTG3vzU6l2fTZUvt oy+2rk2fdmJ5+nM0EsD4ITLaXdURPSkf7zDg87XPhU7TtBrO7Y/15PkDVR5Hqdik 8hRvT9wvIX5gLEpobbgSRbt5Df/dlybdnbKBHax70RcrSaSYAYuZ6Si0v0e6TD/q Sb4zaShPh+JPLMHGh1zNMB/tAtci51tWfSMJ1E+8psC3qUx7ZNc= =Emmr -----END PGP SIGNATURE-----