Debian Patches

Status for libquartz-java/1:1.8.6-8

Patch Description Author Forwarded Bugs Origin Last update
disable_update_check_864769.patch disable update checks by default To override this behavior, set org.quartz.scheduler.skipUpdateCheck=false
in quartz.properties.
tony mancill <tmancill@debian.org> not-needed debian
j2ee-dependencies.patch Depend on the individual JEE spec jars instead of the big all in one artifact. Emmanuel Bourg <ebourg@apache.org> not-needed
CVE-2019-13990.patch patch for CVE-2019-13990 The method initDocumentParser() in the XMLSchedulingDataProcessor.java
does not forbid DTDs, which allows a context-dependend attacker to
perform an XXE.
.
The testcase in the patch is slightly adapted for quartz 1.8.6
not-needed debian https://github.com/quartz-scheduler/quartz/commit/a1395ba118df306c7fe67c24fb0c9a95a4473140 2023-01-29

All known versions for source package 'libquartz-java'

Links