Re: Security update of mysql-connector-java

2016-07-06 Thread Emmanuel Bourg
Le 6/07/2016 à 22:12, Markus Koschany a écrit : > Can I go ahead with an upload to jessie-security? Don't forget to fix the regression with Java 8 before uploading (#828836). I can help if necessary. Emmanuel Bourg

Re: Security update of mysql-connector-java

2016-07-06 Thread Moritz Mühlenhoff
On Wed, Jun 22, 2016 at 06:19:08PM +0200, Markus Koschany wrote: > On 22.06.2016 08:47, Moritz Mühlenhoff wrote: > > On Wed, Jun 22, 2016 at 01:01:14AM +0200, Markus Koschany wrote: > >> On 22.06.2016 00:43, Emmanuel Bourg wrote: > >>> Le 22/06/2016 à 00:28, Markus Koschany a écrit : > >>> > H

Re: Security update of mysql-connector-java

2016-07-06 Thread Markus Koschany
On 22.06.2016 18:19, Markus Koschany wrote: > On 22.06.2016 08:47, Moritz Mühlenhoff wrote: >> On Wed, Jun 22, 2016 at 01:01:14AM +0200, Markus Koschany wrote: >>> On 22.06.2016 00:43, Emmanuel Bourg wrote: Le 22/06/2016 à 00:28, Markus Koschany a écrit : > Houston, we have a problem.

Re: Security update of mysql-connector-java

2016-06-22 Thread Markus Koschany
On 22.06.2016 08:47, Moritz Mühlenhoff wrote: > On Wed, Jun 22, 2016 at 01:01:14AM +0200, Markus Koschany wrote: >> On 22.06.2016 00:43, Emmanuel Bourg wrote: >>> Le 22/06/2016 à 00:28, Markus Koschany a écrit : >>> Houston, we have a problem. It seems the latest upstream release requires

Re: Security update of mysql-connector-java

2016-06-21 Thread Moritz Mühlenhoff
On Wed, Jun 22, 2016 at 01:01:14AM +0200, Markus Koschany wrote: > On 22.06.2016 00:43, Emmanuel Bourg wrote: > > Le 22/06/2016 à 00:28, Markus Koschany a écrit : > > > >> Houston, we have a problem. It seems the latest upstream release > >> requires Java 8 for building JDBC 4. In Jessie even Java

Re: Security update of mysql-connector-java

2016-06-21 Thread Markus Koschany
On 22.06.2016 00:43, Emmanuel Bourg wrote: > Le 22/06/2016 à 00:28, Markus Koschany a écrit : > >> Houston, we have a problem. It seems the latest upstream release >> requires Java 8 for building JDBC 4. In Jessie even Java 6 was >> sufficient. I suggest we ship version 5.1.34 of mysql-connector-j

Re: Security update of mysql-connector-java

2016-06-21 Thread Emmanuel Bourg
Le 22/06/2016 à 00:28, Markus Koschany a écrit : > Houston, we have a problem. It seems the latest upstream release > requires Java 8 for building JDBC 4. In Jessie even Java 6 was > sufficient. I suggest we ship version 5.1.34 of mysql-connector-java > instead, which should build fine with Java 6

Re: Security update of mysql-connector-java

2016-06-21 Thread Markus Koschany
On 20.06.2016 19:41, Markus Koschany wrote: > On 20.06.2016 19:38, Moritz Muehlenhoff wrote: >> On Mon, Jun 20, 2016 at 06:48:58PM +0200, Markus Koschany wrote: >>> Hello, >>> >>> I am thinking about to upgrade mysql-connector-java to the latest stable >>> version in Wheezy and Jessie to address >>

Re: Security update of mysql-connector-java

2016-06-20 Thread Markus Koschany
On 20.06.2016 19:38, Moritz Muehlenhoff wrote: > On Mon, Jun 20, 2016 at 06:48:58PM +0200, Markus Koschany wrote: >> Hello, >> >> I am thinking about to upgrade mysql-connector-java to the latest stable >> version in Wheezy and Jessie to address >> >> https://security-tracker.debian.org/tracker/CVE

Re: Security update of mysql-connector-java

2016-06-20 Thread Moritz Muehlenhoff
On Mon, Jun 20, 2016 at 06:48:58PM +0200, Markus Koschany wrote: > Hello, > > I am thinking about to upgrade mysql-connector-java to the latest stable > version in Wheezy and Jessie to address > > https://security-tracker.debian.org/tracker/CVE-2015-2575 > > As usual Oracle does not provide conc

Security update of mysql-connector-java

2016-06-20 Thread Markus Koschany
Hello, I am thinking about to upgrade mysql-connector-java to the latest stable version in Wheezy and Jessie to address https://security-tracker.debian.org/tracker/CVE-2015-2575 As usual Oracle does not provide concrete information about the vulnerability or a patch for older versions. On the ot