changes_fields:
Architecture: all
Binary: libcommons-net-java
Changed-By: Markus Koschany <apo@debian.org>
Changes: |2-
libcommons-net-java (3.9.0-1) unstable; urgency=medium
.
* Team upload.
* New upstream version 3.9.0. (Closes: #1025910)
Fix CVE-2021-37533: Prior to Apache Commons Net 3.9.0, Net's FTP client
trusts the host from PASV response by default. A malicious server can
redirect the Commons Net code to use a different host, but the user has to
connect to the malicious server in the first place. This may lead to
leakage of information about services running on the private network of the
client. The default in version 3.9.0 is now false to ignore such hosts, as
cURL does.
* Declare compliance with Debian Policy 4.6.2.
* debian:/control:
- Switch to debhelper-compat = 13.
- Use canonical VCS URI.
- Update homepage URL.
- Remove obsolete Breaks and Replaces.
* Remove get-orig-source target.
* Update debian/watch and track github releases.
* Drop orig-tar.sh script.
* Drop libcommons-net-java-doc binary package.
Checksums-Sha1:
- name: libcommons-net-java_3.9.0-1_all.deb
sha1: 87ad204ebdebc556e466bdd828370f5bf6e6d7d4
size: '293880'
- name: libcommons-net-java_3.9.0-1_arm64.buildinfo
sha1: de414aa45efef2575557b77c978d5ae93c2a590d
size: '14252'
Checksums-Sha256:
- name: libcommons-net-java_3.9.0-1_all.deb
sha256: d04f9567b418e8804071080168396462588e50cb19bbd68a3bd2b0ab773f8395
size: '293880'
- name: libcommons-net-java_3.9.0-1_arm64.buildinfo
sha256: dffdc4c76f77c3054eb8d00ef4bd4f948ac7a43a89abe394a1da5ce244f3c10f
size: '14252'
Closes: '1025910'
Date: Tue, 27 Dec 2022 16:24:48 +0100
Description: |2-
libcommons-net-java - Apache Commons Net - Java client API for basic Internet protocols
Distribution: sid
Files:
- md5sum: f5da244ac7443e566d4ab62b9c71e03f
name: libcommons-net-java_3.9.0-1_all.deb
priority: optional
section: java
size: '293880'
- md5sum: 26f10b240eaf7c0beab473631d4988f1
name: libcommons-net-java_3.9.0-1_arm64.buildinfo
priority: optional
section: java
size: '14252'
Format: '1.8'
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Source: libcommons-net-java
Urgency: medium
Version: 3.9.0-1
type: dpkg