Import Debian changes 42.2.15-1+deb11u1
libpgjava (42.2.15-1+deb11u1) bullseye-security; urgency=high . * Team upload. * Fix CVE-2022-26520: An attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. * Fix CVE-2022-21724: The JDBC driver did not verify if certain classes implemented the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes.
Showing
- debian/changelog 14 additions, 0 deletionsdebian/changelog
- debian/patches/CVE-2022-21724.patch 197 additions, 0 deletionsdebian/patches/CVE-2022-21724.patch
- debian/patches/CVE-2022-26520.patch 367 additions, 0 deletionsdebian/patches/CVE-2022-26520.patch
- debian/patches/series 2 additions, 0 deletionsdebian/patches/series
debian/patches/CVE-2022-21724.patch
0 → 100644
debian/patches/CVE-2022-26520.patch
0 → 100644
Please register or sign in to comment