Re: Bug#760733: libspring-java: CVE-2014-0225

2014-11-26 Thread Emmanuel Bourg
Le 26/11/2014 12:41, Moritz Muehlenhoff a écrit : > I didn't look into the specific issue, but Red Hat Bugzilla has > references to isolated patches? > > https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0225 I don't know why the title of the mail refers to CVE-2014-0225, but the bug #760733

Re: Bug#760733: libspring-java: CVE-2014-0225

2014-11-26 Thread Moritz Muehlenhoff
On Wed, Nov 26, 2014 at 12:40:37PM +0100, Emmanuel Bourg wrote: > I've been investigating this issue as well. I contacted an upstream > developer and it seems the actual fix for this issue is unknown. The > version 3.2.0 was just reported as not vulnerable by the security > researched who discovere

Re: Bug#760733: libspring-java: CVE-2014-0225

2014-11-26 Thread Emmanuel Bourg
I've been investigating this issue as well. I contacted an upstream developer and it seems the actual fix for this issue is unknown. The version 3.2.0 was just reported as not vulnerable by the security researched who discovered this issue. I can prepare an upgrade to the latest 3.2.x version but

libspring-java: CVE-2014-0225

2014-11-26 Thread Stephen Nelson
On 26 Nov 2014 10:45, "Raphael Hertzog" wrote: > > Hello Stephen, > > On Mon, 08 Sep 2014, Stephen Nelson wrote: > > > For what it's worth, CVE-2014-3578 was assigned to a directory traversal > > > vulnerability in libspring-java > > > ( http://www.pivotal.io/security/cve-2014-3578) > > > > Thanks