-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 29 Aug 2022 13:53:39 CEST Source: maven-shared-utils Architecture: source Version: 3.3.0-1+deb10u1 Distribution: buster-security Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> Changed-By: Markus Koschany <apo@debian.org> Checksums-Sha1: 6fd129a67df654a399c5c2967c9407f737248201 2535 maven-shared-utils_3.3.0-1+deb10u1.dsc 56d7890696c253da39ef7dc878098965ccd487c0 119656 maven-shared-utils_3.3.0.orig.tar.xz 4847807d8f6a38b3efc1a8e8a2cbdba9dfd0d1f9 6372 maven-shared-utils_3.3.0-1+deb10u1.debian.tar.xz c1496f4c670ecff86e74849380d837e7ff3934ed 16083 maven-shared-utils_3.3.0-1+deb10u1_amd64.buildinfo Checksums-Sha256: efc122f0368e26f7ce7d5a68467581774759440cc81a73c02de0ea27ca403f30 2535 maven-shared-utils_3.3.0-1+deb10u1.dsc 11b00155d894a7e5f2bd4a0f81ca2b34236496019fdf9492aa458355fd16d674 119656 maven-shared-utils_3.3.0.orig.tar.xz 6bdcf16bdaf6a8cf646f2c3a3a09470fc610b3408aed963316ce4f3c1c22568b 6372 maven-shared-utils_3.3.0-1+deb10u1.debian.tar.xz be6475afbcca08eb235951e7f4478a01d2daad6673d0274780f2e05361ab5abc 16083 maven-shared-utils_3.3.0-1+deb10u1_amd64.buildinfo Changes: maven-shared-utils (3.3.0-1+deb10u1) buster-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2022-29599: Apache Maven maven-shared-utils, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks. Files: 50ad7767a3ef04b183d4327109f5b71c 2535 java optional maven-shared-utils_3.3.0-1+deb10u1.dsc e8986bb1ea7745c6bbf4dca7a2f8443a 119656 java optional maven-shared-utils_3.3.0.orig.tar.xz 5ab45b2505061eb2aae247a2266b838b 6372 java optional maven-shared-utils_3.3.0-1+deb10u1.debian.tar.xz 590f87ba8d0f9a7877f3dd4bebd72cf6 16083 java optional maven-shared-utils_3.3.0-1+deb10u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmMMqNVfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkZjkQALdvn0S48UFlrmwJgToZ99y/AVWaqWYoouhv GWoc/6kK0i/LaF6itoMqNeueg0Lyayoll/amA4amDl1xOwevY87VomKhGoaIIY+B PxAkq8QksJgYr6ohW4JPEWANhp+cJQD6o+Lqvn9lxuW7v9E20iEjcqzTW5Bml+pe ClohTG+owVBOuVYbW8IywVE7xdaSrUOAPBWexAm9UNa70k+NoIR52tvhKG6MpzrG zx4Xwj15Rfxd+tkZfac+sIgWBqRCBps16TznUZ8iyil3EJOMl+URUtCGkXktGQcr Vquwra38WhT5EPkrmNwEqyI/2Xv3Jg2uHuSXlOVm526YPydWz4uT98lKU+lL28TR g2/OMN/O6xkZzAnyEnPXLyrCay0hinkIsXB+jYGsxhSFRv64CdwpaOzssGrm6NC2 Tfma/kZPL9vR572ifVsQrvXVEoW0P/GGhXswtfOxs9JMdkxch14JsoWaqBzfRGLn HCtFuyCzJOu85Ejov7fbJn75vARrZKRK265xHL6H8ZK7GUtI38qvJU7oAfbjeKBk QZtANMBmQAlOYN6SQz276s0qkm83cVfO//Xca7VjXmajciTgN/mYmntd5uIHv+qg G7wL+8ZcerEWprKhM1zTF9pJHChUZcL0l3qu7g1+nlqJO650HQuWknmczgJivNZL O7DhBPfS =Olpe -----END PGP SIGNATURE-----
Attachment:
pgpisgWBgrWMu.pgp
Description: PGP signature