Re: Propose to ignore libxstream-java CVEs

2021-09-22 Thread Markus Koschany
Hi all, so far I have not found any regressions in Debian packages which depend on libxstream-java. I propose to switch to the whitelist in all suites because this is the only reasonable way to secure XStream. I have prepared an update for Stretch. Anton, could you take a look at it because I saw

Re: Propose to ignore libxstream-java CVEs

2021-09-22 Thread Sylvain Beucler
Hi, On 22/09/2021 15:37, Markus Koschany wrote: so far I have not found any regressions in Debian packages which depend on libxstream-java. I propose to switch to the whitelist in all suites because this is the only reasonable way to secure XStream. I have prepared an update for Stretch. Anton,

Re: Propose to ignore libxstream-java CVEs

2021-09-22 Thread Sylvain Beucler
Hi, On Wed, Sep 22, 2021 at 04:29:39PM +0200, Sylvain Beucler wrote: > On 22/09/2021 15:37, Markus Koschany wrote: > > so far I have not found any regressions in Debian packages which depend on > > libxstream-java. I propose to switch to the whitelist in all suites because > > this is the only rea