Re: Bug#975016: #975016 - OpenJDK 17 support state for Bullseye

2022-08-17 Thread Salvatore Bonaccorso
Hi Holger, On Wed, Aug 17, 2022 at 10:47:25AM +, Holger Levsen wrote: > hi, > > as both openjdk-11 and openjdk-17 have received security updates and > as I understand this very bug report, we can close this bug as nothing > regarding the security-status of openjdk-(11|17) in bullseye needs to

Re: libpdfbox-java security update

2016-06-12 Thread Salvatore Bonaccorso
Hi Markus, On Sun, Jun 12, 2016 at 02:50:42PM +0200, Markus Koschany wrote: > Hi, > > I have prepared a security update for libpdfbox-java (Jessie). Please > find attached the proposed debdiff. Thanks for your work on it. In this case Emmanuel Bourg is already on it. We though agreed with him to

Call for testing: libapache-mod-jk fixing CVE-2014-8111

2015-05-26 Thread Salvatore Bonaccorso
Hi Markus Koschany prepared updated package for libapache-mod-jk for wheezy-security and jessie-security. If you run libapache-mod-jk in production testing of the prepared packages would be very welcome. If you find a problem introduced by updating to these packages, please report the problem dire

Re: libapache-mod-jk: CVE-2014-8111

2015-05-25 Thread Salvatore Bonaccorso
Hi Markus, On Mon, May 25, 2015 at 05:10:48PM +0200, Markus Koschany wrote: > Hello Salvatore, > > On 25.05.2015 09:21, Salvatore Bonaccorso wrote: > [...] > >> I think the issue warrants a DSA since it is remotely exploitable > >> although the severity and impact

Re: libapache-mod-jk: CVE-2014-8111

2015-05-25 Thread Salvatore Bonaccorso
Hello Markus, On Mon, May 25, 2015 at 12:35:04AM +0200, Markus Koschany wrote: > Hello security team, > > I have prepared two security updates for libapache-mod-jk which is > affected by CVE-2014-8111 [1] in Jessie and Wheezy. This is Debian bug > #783233 [2]. Thanks for preparing the update. >

Re: Tomcat version for jessie

2014-04-28 Thread Salvatore Bonaccorso
Hi, On Mon, Apr 28, 2014 at 02:16:13PM +0200, Emmanuel Bourg wrote: > Le 28/04/2014 13:22, Moritz Muehlenhoff a écrit : > > Hi, > > I noticed that tomcat8 was uploaded into sid. We still have tomcat6 and > > tomcat7 in > > jessie, can we remove these so that there's only one update that needs to