On Mon, Mar 24, 2014 at 04:46:02PM -0300, Miguel Landaeta wrote:
> I believe a DSA is not necessary for those CVEs.
>
I want to rectify on this. I think a DSA is necessary because the fix
for CVE-2014-0054 addresses an incomplete fix for CVE-2013-4152 /
CVE-2013-6429 and some of those vulnerabili
owner 741604 !
tags 741604 + confirmed
thanks
On Fri, Mar 14, 2014 at 01:24:47PM +0100, Moritz Muehlenhoff wrote:
> Package: libspring-java
> Severity: grave
> Tags: security
> Justification: user security hole
>
> http://www.gopivotal.com/security/cve-2014-0054
> http://www.gopivotal.com/securit
Package: libspring-java
Severity: grave
Tags: security
Justification: user security hole
http://www.gopivotal.com/security/cve-2014-0054
http://www.gopivotal.com/security/cve-2014-1904
I'm not sure whether these are worth a DSA?
Cheers,
Moritz
--
To UNSUBSCRIBE, email to debian-bugs-r
3 matches
Mail list logo