Bug 22472

Summary: apache-poi new security issue CVE-2017-12626
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Java Stack Maintainers <java>
Status: RESOLVED DUPLICATE QA Contact: Sec team <security>
Severity: normal    
Priority: Normal    
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA6TOO
Source RPM: apache-poi-3.14-1.mga6.src.rpm CVE:
Status comment: Fixed upstream in 3.17

Description David Walser 2018-01-27 12:00:00 CET
Upstream has issued an advisory on January 26:
http://openwall.com/lists/oss-security/2018/01/26/7

The issue is fixed in 3.17.

Mageia 5 and Mageia 6 are also affected.
David Walser 2018-01-27 12:00:09 CET

Whiteboard: (none) => MGA6TOO

David Walser 2018-02-02 18:32:14 CET

Status comment: (none) => Fixed upstream in 3.17

Comment 1 David Walser 2019-01-01 04:59:09 CET
Already noted in Bug 19029.

*** This bug has been marked as a duplicate of bug 19029 ***

Resolution: (none) => DUPLICATE
Status: NEW => RESOLVED