-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 21 Jan 2018 20:09:22 +0100 Source: lucene-solr Binary: liblucene3-java liblucene3-contrib-java liblucene3-java-doc libsolr-java solr-common solr-tomcat solr-jetty Architecture: source all Version: 3.6.0+dfsg-1+deb7u3 Distribution: wheezy-security Urgency: high Maintainer: Debian Java Maintainers <pkg-java-maintain...@lists.alioth.debian.org> Changed-By: Markus Koschany <a...@debian.org> Description: liblucene3-contrib-java - Full-text search engine library for Java(TM) liblucene3-java - Full-text search engine library for Java(TM) liblucene3-java-doc - Documentation for Lucene libsolr-java - Enterprise search server based on Lucene - Java libraries solr-common - Enterprise search server based on Lucene3 - common files solr-jetty - Enterprise search server based on Lucene3 - Jetty integration solr-tomcat - Enterprise search server based on Lucene3 - Tomcat integration Changes: lucene-solr (3.6.0+dfsg-1+deb7u3) wheezy-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix CVE-2017-12629: possible remote code execution by exploiting XXE. For security reasons the RunExecutableListener class was permanently removed. * Update debian/conf/solrconfig.xml and remove example configuration for. RunExecutableListener which had to be removed for security reasons. Checksums-Sha1: be34826f97f43208dc52904fc09adfb22b25be44 3371 lucene-solr_3.6.0+dfsg-1+deb7u3.dsc 3e8f6cdae7b6fa532c1516e52c0e66e9cc8fc953 47748 lucene-solr_3.6.0+dfsg-1+deb7u3.debian.tar.xz 469dae08d88ce1d67aba7d884d73808e21bff869 1511844 liblucene3-java_3.6.0+dfsg-1+deb7u3_all.deb 9b786ca1c7597fdab49c3875c24a02890fef3156 11154334 liblucene3-contrib-java_3.6.0+dfsg-1+deb7u3_all.deb a87ec7505497447b4ff4b4a78b9b16fa63a579ab 10035450 liblucene3-java-doc_3.6.0+dfsg-1+deb7u3_all.deb 0e8a9fef1405ae85b08d77f1e44eef3f0137140a 2026116 libsolr-java_3.6.0+dfsg-1+deb7u3_all.deb 4947818f903ca428b47b4e9ab4fd9878b8e17511 172390 solr-common_3.6.0+dfsg-1+deb7u3_all.deb 145648c3a811a3166514ce602224eaecbe8ae1f2 8374 solr-tomcat_3.6.0+dfsg-1+deb7u3_all.deb b42f342ec1f8b8b4ebbc008498e2db3412ea6b44 7932 solr-jetty_3.6.0+dfsg-1+deb7u3_all.deb Checksums-Sha256: 9c66ed043ce855f03f432fb6cad2d57123109b9c266303d062818a6e0f547bce 3371 lucene-solr_3.6.0+dfsg-1+deb7u3.dsc 97e46909d7c1194c083cc444fb9d00d2b510060c41117e873157752da04158aa 47748 lucene-solr_3.6.0+dfsg-1+deb7u3.debian.tar.xz 9e4eb4691d5d071a3873946abcd2700b781e0a86d1ecd1ae23871461574f2542 1511844 liblucene3-java_3.6.0+dfsg-1+deb7u3_all.deb a0437e4e257a271711f719669fb26ff935ce4ad06496382543b6afd69963f635 11154334 liblucene3-contrib-java_3.6.0+dfsg-1+deb7u3_all.deb 46bba83f4aa3757a3d3176de4701d2f16c2410b377f776a5c44f1b5f5fef0889 10035450 liblucene3-java-doc_3.6.0+dfsg-1+deb7u3_all.deb aea9a18239aebf4aedd380bf1ec0c839a7fa0aa767e074df042cdf1f2d9f5422 2026116 libsolr-java_3.6.0+dfsg-1+deb7u3_all.deb a87f29f3e08b2de962e14822a9d30236c36222f0772cb466ea87cd5ab27da60f 172390 solr-common_3.6.0+dfsg-1+deb7u3_all.deb 10c9298ebbb4a7a55127343016848d240d078ba8c640b328b850799ed4e01173 8374 solr-tomcat_3.6.0+dfsg-1+deb7u3_all.deb 4b964b656bbbc7cd5889b1ea104c7bb0c1f2037a848be8a38521acff0572aa25 7932 solr-jetty_3.6.0+dfsg-1+deb7u3_all.deb Files: 7cd22d22ea7340b71abedfa9f56f36c7 3371 java optional lucene-solr_3.6.0+dfsg-1+deb7u3.dsc 8ed66bb02b0459407bc668267b202952 47748 java optional lucene-solr_3.6.0+dfsg-1+deb7u3.debian.tar.xz bb27c9f4a83c3cc9906eb1406c31709b 1511844 java optional liblucene3-java_3.6.0+dfsg-1+deb7u3_all.deb d4d84b03090ec2b134800ea59f7971c6 11154334 java optional liblucene3-contrib-java_3.6.0+dfsg-1+deb7u3_all.deb c36e3cfa836e911ea0b8c298540eed23 10035450 doc optional liblucene3-java-doc_3.6.0+dfsg-1+deb7u3_all.deb c5866589f71e722b0062c34b7cc366e8 2026116 java optional libsolr-java_3.6.0+dfsg-1+deb7u3_all.deb 704d2d3f3c12ace98a3aececf5da0d33 172390 java optional solr-common_3.6.0+dfsg-1+deb7u3_all.deb f59e6150d617679a3c84f30c2a557a61 8374 java optional solr-tomcat_3.6.0+dfsg-1+deb7u3_all.deb c2cf094ceca0ecc73433223558990f3f 7932 java optional solr-jetty_3.6.0+dfsg-1+deb7u3_all.deb
-----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlpk+n1fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1HkIegQAJuAhPiuiWyIqtHuSMgAR8QtLWxrUV8vhWFJ WEcAGvvhVk+/EKislv75KqV5vGNWrdEyJBz368+MO1l7GAw5QSZ6YuOE3QEQtVL8 OhuWdcZ583sGnfzUBwFTPlhIYCqevDjKeUKuRLo4BJTL/E9ErfBi1MFw5459aCru bohSyb5bZwTqAFxPfumRg22IW9VyGShFN3UNjhpyUX+GEd9qxh25JCqi84vVf+Mz tjb+KhBnV5iVPeETiMdnGvcUM1TPz2o+Z3nonHBNv9R7INW96OJ6+kjXBPovRMD/ q/klfNKFS9tCBg1tleHh/wzkr2fI5YRhcRnEnzec9GOkA1pu1eTC8ia+Slp8hlwu zFhnulRy5J6fuwgw8ncyBhsre//fPYi96EyxJIGfkauevVWebe84QXlWTKJgAc2/ x0/ko+gdjlSf552muMBokxvYm0Ie478ucDzNevkePLFPlu4SHOv3b1V/QXL2WXCb v0DKJqTo5MiBaUA9DAuTUH+J+7jhj7v6XjAgK7Mi+7hlKlokuau49n8sknufb9Ct +ywJ18ItM3OztzMnO3TjcAFW7dfEzN6eOnjb0gV0SFlO8ikqPtXCt+C4Lb/KLuSM ug2th0x+xOobMhDYxCFCvYBQPHejJupYWfHiYhkfrUFV8c7BV8hw+KyB4RE2GHzl QrtCrMMk =Y28n -----END PGP SIGNATURE-----