| Summary: | qpid-proton-java new security issues CVE-2018-17187 and CVE-2019-0223 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | Java Stack Maintainers <java> |
| Status: | RESOLVED OLD | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | mageia |
| Version: | 7 | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | qpid-proton-java-0.12.2-2.mga7.src.rpm | CVE: | |
| Status comment: | Fixed upstream in 0.30.0 | ||
|
Description
David Walser
2018-11-19 04:45:53 CET
David Walser
2018-11-19 04:46:01 CET
Whiteboard:
(none) =>
MGA6TOO
David Walser
2019-02-03 02:45:56 CET
Status comment:
(none) =>
Fixed upstream in 0.30.0 Apache has issued an advisory today (April 23): https://www.openwall.com/lists/oss-security/2019/04/23/4 The issue is fixed upstream in 0.27.1. Mageia 6 is also affected. Summary:
qpid-proton-java new security issue CVE-2018-17187 =>
qpid-proton-java new security issues CVE-2018-17187 and CVE-2019-0223
David Walser
2019-06-23 19:31:43 CEST
Whiteboard:
MGA6TOO =>
MGA7TOO, MGA6TOO
Nicolas Lécureuil
2020-05-22 14:08:20 CEST
CC:
(none) =>
mageia Not in cauldron anymore Version:
Cauldron =>
7 https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/ Status:
NEW =>
RESOLVED |