File _patchinfo of Package patchinfo.23598
<patchinfo incident="23598">
<issue tracker="bnc" id="1189749">VUL-0: CVE-2021-37714: jsoup: Crafted input may cause the jsoup HTML and XML parser to get stuck</issue>
<issue tracker="cve" id="2021-37714"/>
<packager>fstrba</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for jsoup, jsr-305</summary>
<description>This update for jsoup, jsr-305 fixes the following issues:
- CVE-2021-37714: Fixed infinite in untrusted HTML or XML data parsing (bsc#1189749).
Changes in jsr-305:
- Build with java source and target levels 8
- Upgrade to upstream version 3.0.2
Changes in jsoup:
- Upgrade to upstream version 1.14.2
- Generate tarball using source service instead of a script
</description>
</patchinfo>