| Summary: | xstream new security issue CVE-2017-7957 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | Nicolas Lécureuil <mageia> |
| Status: | RESOLVED OLD | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | geiger.david68210 |
| Version: | 5 | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | xstream-1.4.9-2.mga6.src.rpm | CVE: | CVE-2017-7957 |
| Status comment: | |||
|
Description
David Walser
2017-05-04 12:36:45 CEST
David Walser
2017-05-04 12:36:57 CEST
CC:
(none) =>
geiger.david68210 Fixed in cauldron Version:
Cauldron =>
5
Nicolas Lécureuil
2017-05-15 23:53:56 CEST
CVE:
(none) =>
CVE-2017-7957 It sounds like CVE-2017-2608 affects jenkins, or jenkins-xstream, or xstream: http://openwall.com/lists/oss-security/2017/05/22/2 We won't be fixing this type of package for Mageia 5. Resolution:
(none) =>
OLD |