Re: Propose to ignore CVE-2022-41853 for hsqldb

2022-10-31 Thread Ola Lundqvist
Hi Good suggestion. I have added the package to dla-needed.txt and referred to this email chain. Cheers // Ola On Mon, 31 Oct 2022 at 13:53, Markus Koschany wrote: > Hi Ola, > > Am Montag, dem 31.10.2022 um 12:55 +0100 schrieb Ola Lundqvist: > > > > Any other thoughts? > > I agree this is a p

Re: Propose to ignore CVE-2022-41853 for hsqldb

2022-10-31 Thread Markus Koschany
Hi Ola, Am Montag, dem 31.10.2022 um 12:55 +0100 schrieb Ola Lundqvist: > > Any other thoughts? I agree this is a possible breaking change. I suggest we fix unstable first and investigate the further implications. I will do that soon. I have updated the security tracker with information about th

Propose to ignore CVE-2022-41853 for hsqldb

2022-10-31 Thread Ola Lundqvist
Hi fellow LTS developers I have looked at hsqldb and CVE-2022-41853. https://security-tracker.debian.org/tracker/CVE-2022-41853 >From the description it is clear that there are methods to configure the system to make it secure. The software change is to not allow any classes to be used by default