Bug#933169: libquartz-java: CVE-2019-13990: XXE in initDocumentParser

2019-10-07 Thread Salvatore Bonaccorso
Hi On Sat, Jul 27, 2019 at 08:22:26AM +0200, Salvatore Bonaccorso wrote: > Source: libquartz-java > Version: 1:1.8.6-6 > Severity: important > Tags: security upstream > Forwarded: https://github.com/quartz-scheduler/quartz/issues/467 FWIW, it looks there is now an upstream patch for this issue if

Bug#933169: libquartz-java: CVE-2019-13990: XXE in initDocumentParser

2019-07-26 Thread Salvatore Bonaccorso
Source: libquartz-java Version: 1:1.8.6-6 Severity: important Tags: security upstream Forwarded: https://github.com/quartz-scheduler/quartz/issues/467 Control: found -1 1:1.8.6-3 Control: clone -1 -2 Control: reassign -2 src:libquartz2-java 2.3.0-2 Control: retitle -2 libquartz2-java: CVE-2019-1399