Re: [Codec] Question about security implication of CODEC-113 issue in tracker

2013-03-25 Thread sebb
On 25 March 2013 03:16, Gary Gregory wrote: > I thik it's up to you to decide what > http://findbugs.sourceforge.net/bugDescriptions.html#MS_PKGPROTECT means > for your customers. Also (as per the ticket) the issue was fixed in 1.5. The current release is 1.7. > Gary > > > On Sun, Mar 24, 2013 a

Re: [Codec] Question about security implication of CODEC-113 issue in tracker

2013-03-24 Thread Gary Gregory
I thik it's up to you to decide what http://findbugs.sourceforge.net/bugDescriptions.html#MS_PKGPROTECT means for your customers. Gary On Sun, Mar 24, 2013 at 5:10 PM, Brian Martin < br...@opensecurityfoundation.org> wrote: > > Apache Commons project; > > Gary, the ticket reporter, indicated I

[Codec] Question about security implication of CODEC-113 issue in tracker

2013-03-24 Thread Brian Martin
Apache Commons project; Gary, the ticket reporter, indicated I should email the list to ask my question. I am not familiar with Java or the Commons project in detail, but was hoping someone could briefly explain this ticket in the context of security: https://issues.apache.org/jira/browse