-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 28 Sep 2025 15:38:53 +0200 Source: log4cxx Built-For-Profiles: noudeb Architecture: source Version: 1.4.0-1.1 Distribution: unstable Urgency: medium Maintainer: Tobias Frost <tobi@debian.org> Changed-By: Lukas Märdian <slyon@debian.org> Closes: 1111879 1111881 Changes: log4cxx (1.4.0-1.1) unstable; urgency=medium . * Non-maintainer upload. * Security fixes for CVE-2025-54812 & CVE-2025-54813 from upstream: - d/p/{04,05}-cve-2025-54812*: (Closes: #1111879) + Escape any logger name '&' or '"' in html attribute data (PR#509) + Escape any thread name '&' or '"' in html attribute data (PR#514) - d/p/06-cve-2025-54813*: (Closes: #1111881) + Escape control characters in JSONLayout data (PR#512) Checksums-Sha1: 211ba29b8e26a3d6e3456293dbfa099713df5404 2425 log4cxx_1.4.0-1.1.dsc f20dcb5fa935eca9f758426189dacd6bb4809399 80432 log4cxx_1.4.0-1.1.debian.tar.xz 4263c27b21681cb9710250fe1a07b869cddb3340 9292 log4cxx_1.4.0-1.1_source.buildinfo Checksums-Sha256: 2ac25c7d5da935dbfa95906d456615f6c1910a6a881dc52ece60f725d7945e9b 2425 log4cxx_1.4.0-1.1.dsc 1f97cb341a18d89a4f813776c663e7a11dd8c00b220e0ce161f83f856e968a13 80432 log4cxx_1.4.0-1.1.debian.tar.xz 4bf71fdac553e15550794b9a7845ce187abcecdf22fe4a4853be9b9518ddcd6d 9292 log4cxx_1.4.0-1.1_source.buildinfo Files: 5fad5227a237bbf1997b76851445582a 2425 devel optional log4cxx_1.4.0-1.1.dsc bc0dd1dca9e2d638428f13f14cf0d204 80432 devel optional log4cxx_1.4.0-1.1.debian.tar.xz c695a4444cc7921ebb38d3f7595c7664 9292 devel optional log4cxx_1.4.0-1.1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEco7DU8UfXhRO0oCBM4dveyhIiTsFAmjZVUoACgkQM4dveyhI iTs/3hAAh4Lt3mcEXj/YSYYuhCFOiFQdApdm0fb51NKJYRlAV8QdI1DhSWWqoYqM M5scuhgJ9kUPpRMqYEBh6lozCx8OIRx1r9BDYOpzC6ShVDRlCY1EeODmg7gEj7l3 dIEMRY8HT/SPP42p9pjG5h9fZjbm4k5OzaNMn1Ig5crVOEAuz0NN5BnblYuHOii3 rs5xkbjKKb5QgfGWyX0NgMcT4lkxkriakKWxtagsEwSpzmf9u08F9qTeC3veAwnC g5kBBZ2DrsVmaWyx21sg22r7FF/uA3JpQIflMS9o5Jw7jnD4cO3kxm9hb1zQaWuh wR5wLjdGntr0U5Q+dCvk5gfJiOy4Ozlh39UykzIXP/YT0Bc1lTjXV6Dki54hkVkS cn8zxw6OLgk8qmfkCymEQY5eYt29lNq4yObYvDnqFI7SnwYps2VkYGSuFHFO4kSe X8/8UrQbI78IeS1KPcWfjIaXB7mshsshluSj9VmPeEGbaAqHlnGSMT/GwL1wA02u USHSfnf6lmR/4LCz8UrdbeOrujnfpliFc+q4c2j0bkb0jO26Om8QdKE5CdUOdZt9 bRPR3cDrzF4KdKJ38SoTBjvd7ouC0J6ueoPaU8kvcKTXQX0QZQ2XbAINvNnxuwVk kIxJyUI6gMTReNOiSc2QIhAIn/0BQt2/Qs7roFmxhBzPGW11Iuk= =ZRYe -----END PGP SIGNATURE-----
Attachment:
pgpL223zywApb.pgp
Description: PGP signature