LTS/ELTS Report for May 2019

2019-06-01 Thread Roberto C . Sánchez
For May I spent 22.25 hours on the following LTS tasks: - ghostscript: CVE-2019-3839, additional cups-filter update - python-urllib3: CVE-2019-11236, CVE-2019-11324 - python3.4, python2.7: CVE-2019-9947, CVE-2019-9740 - libspring-security-2.0-java: CVE-2019-3795 - libav: CVE-2017-17128, CVE-2018-5

RFC: remaining CVEs on libspring-java

2019-06-01 Thread Roberto C . Sánchez
Hello all, I would like some input from the group on how to handle the remaining CVEs (all of which have been tagged no-dsa) on libspring-java: Are are the CVEs which remain open in the jessie version: CVE-2018-1257 CVE-2018-1199 CVE-2018-11040 CVE-2018-11039 CVE-2016-9878 CVE-2016-5007 CVE-2015