Your message dated Tue, 01 Apr 2014 21:17:12 +0000
with message-id <e1wv63u-0003iz...@franck.debian.org>
and subject line Bug#741604: fixed in libspring-java 3.0.6.RELEASE-6+deb7u3
has caused the Debian Bug report #741604,
regarding libspring-java: Multiple security issues
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
741604: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=741604
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: libspring-java
Severity: grave
Tags: security
Justification: user security hole
http://www.gopivotal.com/security/cve-2014-0054
http://www.gopivotal.com/security/cve-2014-1904
I'm not sure whether these are worth a DSA?
Cheers,
Moritz
--- End Message ---
--- Begin Message ---
Source: libspring-java
Source-Version: 3.0.6.RELEASE-6+deb7u3
We believe that the bug you reported is fixed in the latest version of
libspring-java, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 741...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Miguel Landaeta <nomad...@debian.org> (supplier of updated libspring-java
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Mon, 24 Mar 2014 18:12:13 -0300
Source: libspring-java
Binary: libspring-core-java libspring-beans-java libspring-aop-java
libspring-context-java libspring-context-support-java libspring-web-java
libspring-web-servlet-java libspring-web-struts-java libspring-web-portlet-java
libspring-test-java libspring-transaction-java libspring-jdbc-java
libspring-jms-java libspring-orm-java libspring-expression-java
libspring-oxm-java libspring-instrument-java
Architecture: source all
Version: 3.0.6.RELEASE-6+deb7u3
Distribution: wheezy-security
Urgency: high
Maintainer: Debian Java Maintainers
<pkg-java-maintain...@lists.alioth.debian.org>
Changed-By: Miguel Landaeta <nomad...@debian.org>
Description:
libspring-aop-java - modular Java/J2EE application framework - AOP
libspring-beans-java - modular Java/J2EE application framework - Beans
libspring-context-java - modular Java/J2EE application framework - Context
libspring-context-support-java - modular Java/J2EE application framework -
Context Support
libspring-core-java - modular Java/J2EE application framework - Core
libspring-expression-java - modular Java/J2EE application framework -
Expression language
libspring-instrument-java - modular Java/J2EE application framework -
Instrumentation
libspring-jdbc-java - modular Java/J2EE application framework - JDBC tools
libspring-jms-java - modular Java/J2EE application framework - JMS tools
libspring-orm-java - modular Java/J2EE application framework - ORM tools
libspring-oxm-java - modular Java/J2EE application framework - Object/XML
Mapping
libspring-test-java - modular Java/J2EE application framework - Test helpers
libspring-transaction-java - modular Java/J2EE application framework -
transaction
libspring-web-java - modular Java/J2EE application framework - Web
libspring-web-portlet-java - modular Java/J2EE application framework - Portlet
MVC
libspring-web-servlet-java - modular Java/J2EE application framework - Web
Portlet
libspring-web-struts-java - modular Java/J2EE application framework - Struts
MVC
Closes: 741604
Changes:
libspring-java (3.0.6.RELEASE-6+deb7u3) wheezy-security; urgency=high
.
* Team upload.
* Fix CVE-2013-6429 and CVE-2013-6430. (Closes: #741604).
Checksums-Sha1:
e2380a5effbe04a083e44e27a6cd67660ba42d70 4567
libspring-java_3.0.6.RELEASE-6+deb7u3.dsc
7f870e3b6e6185eb0f48ac9ee6ba19012b227a06 29989
libspring-java_3.0.6.RELEASE-6+deb7u3.debian.tar.gz
f8df87ab411e2b4718829da170e776f11e084dc5 366958
libspring-core-java_3.0.6.RELEASE-6+deb7u3_all.deb
a97795cf1610bd3e61103d241e1776407c37f5ec 520342
libspring-beans-java_3.0.6.RELEASE-6+deb7u3_all.deb
200e22fb5ea07e4f491833ca9f95b859e0a990e8 331438
libspring-aop-java_3.0.6.RELEASE-6+deb7u3_all.deb
4c921b70b46226d87ff5aa163931b6352ff8e103 599684
libspring-context-java_3.0.6.RELEASE-6+deb7u3_all.deb
660fcd5d722763520f2f1acf278f01a4a8342531 113860
libspring-context-support-java_3.0.6.RELEASE-6+deb7u3_all.deb
95be66d469acbf0f530ae90344c98ba61ec94bf2 374674
libspring-web-java_3.0.6.RELEASE-6+deb7u3_all.deb
582a50dfdc07417ab74648c357dbe987791c2b4f 399500
libspring-web-servlet-java_3.0.6.RELEASE-6+deb7u3_all.deb
f213aa113b74acb15cfd38520660cf1ae0325566 51806
libspring-web-struts-java_3.0.6.RELEASE-6+deb7u3_all.deb
2d08d13daecbca05881c9cdb3d03b34d2c2d63c7 180504
libspring-web-portlet-java_3.0.6.RELEASE-6+deb7u3_all.deb
5bddd8b58d208c1129e9d58697145cbf21f06be4 205318
libspring-test-java_3.0.6.RELEASE-6+deb7u3_all.deb
306861b169f068cb1f1dbbec8fd06bd12a385595 214484
libspring-transaction-java_3.0.6.RELEASE-6+deb7u3_all.deb
88c2506cd46a5c5dfc64a3b356e9231477f76816 359098
libspring-jdbc-java_3.0.6.RELEASE-6+deb7u3_all.deb
66ae00ab460b8a8335db3ee44578ccf3c6a91738 187094
libspring-jms-java_3.0.6.RELEASE-6+deb7u3_all.deb
bb82bde667dc29e7148007e8d719b0667964c34a 318082
libspring-orm-java_3.0.6.RELEASE-6+deb7u3_all.deb
d3101e74ee5102e436aa10ccec387df601f5869d 176860
libspring-expression-java_3.0.6.RELEASE-6+deb7u3_all.deb
c2d5a3f4cb5447fe668910bd0a03922f2006c0eb 79020
libspring-oxm-java_3.0.6.RELEASE-6+deb7u3_all.deb
545ba64cb3d8bd39cec0607d3816301fff6881b7 30250
libspring-instrument-java_3.0.6.RELEASE-6+deb7u3_all.deb
Checksums-Sha256:
f50faeaf12d401e7f7d50471fb9aa454125db4d801769980aa731a600ec3196d 4567
libspring-java_3.0.6.RELEASE-6+deb7u3.dsc
3f8d417d8b1ff5bd9bd7c123e91d99c1b9df09f97fdf85d3f8912c59670cde9f 29989
libspring-java_3.0.6.RELEASE-6+deb7u3.debian.tar.gz
f7ffd7bf84501b120f88e1af246e1fb30521c4c0df2b08816784a4a0306d5faf 366958
libspring-core-java_3.0.6.RELEASE-6+deb7u3_all.deb
34d3351b476cdf5b7caa34bf20b2f75cd9354bd15b3d7bda46605fc0899506ac 520342
libspring-beans-java_3.0.6.RELEASE-6+deb7u3_all.deb
9db671e989ffe7bd118ed5d9bc7870f3578ce68fbc8fc1c3c0a3ee03d2f2c423 331438
libspring-aop-java_3.0.6.RELEASE-6+deb7u3_all.deb
7640c9843b8f90349018c4d33f5430dd0c736177e2eb00382793384dea71c098 599684
libspring-context-java_3.0.6.RELEASE-6+deb7u3_all.deb
3d56a527b965d8c163e27375f97f1fda8789ae2ab76f3f70e710ba86fc9cad12 113860
libspring-context-support-java_3.0.6.RELEASE-6+deb7u3_all.deb
6e00cb8e01d198210b72ee6fbd49b530a610ffd6180c31b7cc05c7042145c2d5 374674
libspring-web-java_3.0.6.RELEASE-6+deb7u3_all.deb
d33f973adfa72107b82c0eba600460d4b9aea3d0c5174325c2e15caded48f55b 399500
libspring-web-servlet-java_3.0.6.RELEASE-6+deb7u3_all.deb
1d5a3f62c3eae1f1a7e86b51c7f180439cb88a8905ddf1238cb6236ce8f8a2c3 51806
libspring-web-struts-java_3.0.6.RELEASE-6+deb7u3_all.deb
18b3c4315afa969d94bb20a96218a026e49f9868db1527db179322ad6e163d15 180504
libspring-web-portlet-java_3.0.6.RELEASE-6+deb7u3_all.deb
27063f0101fd6b0ee268af66aeb592e15b6d1ce5dddc13e28a1bd91260ef0e2a 205318
libspring-test-java_3.0.6.RELEASE-6+deb7u3_all.deb
88e4639e2d59ffe89cc3f81928fd9ab0f212741a60db659aceb5af29b399790d 214484
libspring-transaction-java_3.0.6.RELEASE-6+deb7u3_all.deb
bf1500c87fbc2f3586a51e9831a532ca7078e24efb1a30360e49234b5c896b68 359098
libspring-jdbc-java_3.0.6.RELEASE-6+deb7u3_all.deb
61f7dee47728f70a40ad4afdd4906309ccab453a6ab2da41bf2136c921d2ab75 187094
libspring-jms-java_3.0.6.RELEASE-6+deb7u3_all.deb
6b3984f6d7f81c4db59dd2a315ad1968ad5e87ccb30c56f07337f508809be7e1 318082
libspring-orm-java_3.0.6.RELEASE-6+deb7u3_all.deb
5dc6b964e59cb42fab9862d7f453f7024124629680361008b6417ee1aa6e14a7 176860
libspring-expression-java_3.0.6.RELEASE-6+deb7u3_all.deb
04bfb5f55b655b90137504a22ff517106c91dbb7607a37a04a055a0d7a25edde 79020
libspring-oxm-java_3.0.6.RELEASE-6+deb7u3_all.deb
30980b509e89c6ade4915eb9dcb8fe0ac030097e0a53c8868204ac9fc4d23484 30250
libspring-instrument-java_3.0.6.RELEASE-6+deb7u3_all.deb
Files:
9a7b46425c7497c47e7de3a80bfb5a00 4567 java extra
libspring-java_3.0.6.RELEASE-6+deb7u3.dsc
9587b4b88292e9987359c0055024a83a 29989 java extra
libspring-java_3.0.6.RELEASE-6+deb7u3.debian.tar.gz
3aec5115dc66b1100e7c22f5461e0d65 366958 java extra
libspring-core-java_3.0.6.RELEASE-6+deb7u3_all.deb
7f2a565176394c7a3b40f0793097250c 520342 java extra
libspring-beans-java_3.0.6.RELEASE-6+deb7u3_all.deb
1e45312e5590d58e3859de0bbb685b6b 331438 java extra
libspring-aop-java_3.0.6.RELEASE-6+deb7u3_all.deb
7744dfb2818b305b53306f36ca7a93b3 599684 java extra
libspring-context-java_3.0.6.RELEASE-6+deb7u3_all.deb
133143a2d56e6deb52c22679f3a0baba 113860 java extra
libspring-context-support-java_3.0.6.RELEASE-6+deb7u3_all.deb
0625de71320fdf79b35f732ff2e0890c 374674 java extra
libspring-web-java_3.0.6.RELEASE-6+deb7u3_all.deb
0f5a809177cb8043d08edc2263bf2405 399500 java extra
libspring-web-servlet-java_3.0.6.RELEASE-6+deb7u3_all.deb
1117f6d03d0c6e3b08236d7ea144227c 51806 java extra
libspring-web-struts-java_3.0.6.RELEASE-6+deb7u3_all.deb
f208796577028eab7b24eb496e1c0e96 180504 java extra
libspring-web-portlet-java_3.0.6.RELEASE-6+deb7u3_all.deb
d42fc8e8e08ddd4b5c8f032f80378ae2 205318 java extra
libspring-test-java_3.0.6.RELEASE-6+deb7u3_all.deb
eb6198c9363be6a5d61325abb6021691 214484 java extra
libspring-transaction-java_3.0.6.RELEASE-6+deb7u3_all.deb
937bd995624c105636a5d0ad6c01019f 359098 java extra
libspring-jdbc-java_3.0.6.RELEASE-6+deb7u3_all.deb
9503b6e03deea211e2eab9db2a5bb6de 187094 java extra
libspring-jms-java_3.0.6.RELEASE-6+deb7u3_all.deb
c968814566e26657d134271d7e879acb 318082 java extra
libspring-orm-java_3.0.6.RELEASE-6+deb7u3_all.deb
6ac983bf4f4fc0a3fa9700cd9f0ea626 176860 java extra
libspring-expression-java_3.0.6.RELEASE-6+deb7u3_all.deb
22f3bc10a56e5e6cf831653d79334cb7 79020 java extra
libspring-oxm-java_3.0.6.RELEASE-6+deb7u3_all.deb
70b5447965d3d8a37a85e1bc8febc86a 30250 java extra
libspring-instrument-java_3.0.6.RELEASE-6+deb7u3_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQIcBAEBAgAGBQJTMKvBAAoJEI8AS/UHtGj7p6EQAJZHlJ6pXr9QgUxev+b65mKp
gGF3MHXIcQgA4HYKM7ZAybvcAkbCn4KUmdy2Sspi9T65+Pey06iUAEV3c5v03yl9
TiGfZN6dzWDsfYY4mKiWs9FIDNks/lYz32OExHFANwTg9y8qRc/K9Qbj9R8ENUGc
A0RvVRQDFhl4t3U2A9qfCKmtLkmCEsjFA7OjowcmDAVj7+AAsZOlEu2O9BK6ZJJ4
8PaJbKu7prLI1XkVixLGDl8KE9j1qe7kT8vvhUe8+1gPU7nKCxm8sSw01R0m2IKY
CD7ceo0FyuwVPAPMOP1PzeF+b2piXadqvvzo9RSThAXh0mudGpXZPJhPNzBlCE8V
0K6vRqXtYi98tsOFZZ2XQZu/3XCv+moogwAX2MrlUmDSMWFdUzRIF74kXUALHQWl
xGcMDQRqIWptuMyYuVddg+WHs+IxDibgm5cgXmFBkANg5zKbxLbHuWppqg4PvZ8v
sNkr4Fzgv9fqCpoeOl7FWBaUYKMhODCL9kt3yu3TOE+lOn917jM/xLKroXwmJ7Jh
HKbgdNKfhgpU0/L+/Ho+9bNPI6YEq196T1unCmfk94BHktUUJ/xHPeTnl/9HQAxx
C1op/SyU1OdGFFDlCGFpvOVe2YodUpNCOS7rHNp7aJ87e0hYR0qlNYuGl31d2nE2
oMeJdu6vZQTx0c8osnwy
=ROf5
-----END PGP SIGNATURE-----
--- End Message ---