Warnings:
Could not copy libspring-2.5-java_2.5.6.SEC02.orig.tar.gz to holding; will
attempt to find in DB later
ignoring libspring-2.5-java_2.5.6.SEC02.orig.tar.gz, since it's already in the
archive.
Notes:
Mapping stable-security to proposed-updates.
Accepted:
libspring-2.5-java_2.5.6.SEC02-2+squeeze1.debian.tar.gz
to
main/libs/libspring-2.5-java/libspring-2.5-java_2.5.6.SEC02-2+squeeze1.debian.tar.gz
libspring-2.5-java_2.5.6.SEC02-2+squeeze1.dsc
to main/libs/libspring-2.5-java/libspring-2.5-java_2.5.6.SEC02-2+squeeze1.dsc
libspring-aop-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-aop-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
libspring-aspects-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-aspects-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
libspring-beans-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-beans-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
libspring-context-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-context-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
libspring-context-support-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-context-support-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
libspring-core-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-core-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
libspring-jdbc-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-jdbc-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
libspring-jms-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-jms-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
libspring-orm-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-orm-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
libspring-test-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-test-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
libspring-tx-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-tx-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
libspring-web-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-web-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
libspring-webmvc-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-webmvc-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
libspring-webmvc-portlet-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-webmvc-portlet-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
libspring-webmvc-struts-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
to
main/libs/libspring-2.5-java/libspring-webmvc-struts-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb
Changes:
libspring-2.5-java (2.5.6.SEC02-2+squeeze1) stable-security; urgency=high
.
* Backport fix for CVE-2011-2730: Spring Framework information disclosure
from 2.5.6.SEC03 on upstream maintainance repository (Closes: #677814):
- d/patches/CVE-2011-2730.diff: A new context parameter has been added
called springJspExpressionSupport. When true (the default) the existing
behaviour of evaluating EL within the tag will be performed. When running
in an environment where EL support is provided by the container, it is
strongly recommended that this is set to false
Override entries for your package:
libspring-2.5-java_2.5.6.SEC02-2+squeeze1.dsc - source java
libspring-aop-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
libspring-aspects-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
libspring-beans-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
libspring-context-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
libspring-context-support-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
libspring-core-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
libspring-jdbc-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
libspring-jms-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
libspring-orm-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
libspring-test-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
libspring-tx-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
libspring-web-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
libspring-webmvc-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
libspring-webmvc-portlet-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
libspring-webmvc-struts-2.5-java_2.5.6.SEC02-2+squeeze1_all.deb - extra java
Announcing to [email protected]
Closing bugs: 677814
Thank you for your contribution to Debian.
__
This is the maintainer address of Debian's Java team
<http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-java-maintainers>.
Please use
[email protected] for discussions and questions.