RFS: objenesis 2.1-1

2014-11-26 Thread Markus Koschany
I have packaged the latest upstream version of objenesis since I was also working on easymock 3.3. Both projects are closely related. I have checked that all reverse-dependencies in sid still build from source except two packages that FTBFS due to some other reasons and are not part of testing anyw

Re: Problem with mh_make setup?

2014-11-26 Thread Markus Koschany
On Wed, 26. Nov 17:39 Alastair McKinstry wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Hi, > > I'm packaging thredds, netcdf-java. > After some effort (I'm not really a Java programmer) I got mh_make to > succeed, but when I try to build > the package I get: Hi, could you uplo

RFS: eclipse 3.8.1-7 [RC]

2014-11-26 Thread Markus Koschany
Hi, I think I have fixed the bug that caused all those RC bugs against eclipse and affected other packages like androidsdk-tools. I would appreciate another look though. The new revision is ready in Git. I hope we can get -6 past the release team too. The changes seem to be manageable and I don't

Problem with mh_make setup?

2014-11-26 Thread Alastair McKinstry
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, I'm packaging thredds, netcdf-java. After some effort (I'm not really a Java programmer) I got mh_make to succeed, but when I try to build the package I get: [INFO] Not compiling test sources [INFO] [compiler:testCompile {execution: default-te

Re: Bug#760733: libspring-java: CVE-2014-0225

2014-11-26 Thread Emmanuel Bourg
Le 26/11/2014 12:41, Moritz Muehlenhoff a écrit : > I didn't look into the specific issue, but Red Hat Bugzilla has > references to isolated patches? > > https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0225 I don't know why the title of the mail refers to CVE-2014-0225, but the bug #760733

Re: Bug#760733: libspring-java: CVE-2014-0225

2014-11-26 Thread Moritz Muehlenhoff
On Wed, Nov 26, 2014 at 12:40:37PM +0100, Emmanuel Bourg wrote: > I've been investigating this issue as well. I contacted an upstream > developer and it seems the actual fix for this issue is unknown. The > version 3.2.0 was just reported as not vulnerable by the security > researched who discovere

Re: Bug#760733: libspring-java: CVE-2014-0225

2014-11-26 Thread Emmanuel Bourg
I've been investigating this issue as well. I contacted an upstream developer and it seems the actual fix for this issue is unknown. The version 3.2.0 was just reported as not vulnerable by the security researched who discovered this issue. I can prepare an upgrade to the latest 3.2.x version but

libspring-java: CVE-2014-0225

2014-11-26 Thread Stephen Nelson
On 26 Nov 2014 10:45, "Raphael Hertzog" wrote: > > Hello Stephen, > > On Mon, 08 Sep 2014, Stephen Nelson wrote: > > > For what it's worth, CVE-2014-3578 was assigned to a directory traversal > > > vulnerability in libspring-java > > > ( http://www.pivotal.io/security/cve-2014-3578) > > > > Thanks