This may not actually be an issue for 12.04. From the debian-java list:

> If precise doesn't have libwagon2-java you are probably safe. The
> description of CVE-2013-0253 states that wagon was vulnerable starting
> with the version 2.1. And looking at the patch for wagon 2 [2], none of
> the code modified exists in wagon 1.

[1] https://lists.debian.org/debian-java/2015/02/msg00003.html
[2] 
https://sources.debian.net/src/wagon2/2.2-3%2Bnmu1/debian/patches/cve-2013-0253.patch/

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1136109

Title:
  Upstream security vulnerability in 3.0.4

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/maven/+bug/1136109/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to