Bug 23973

Summary: scala new security issue CVE-2017-15288
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Java Stack Maintainers <java>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: mageia, zombie_ryushu
Version: 7   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: scala-2.10.6-4.mga7.src.rpm CVE: CVE-2017-15288
Status comment: Fixed upstream in 2.10.7

Description David Walser 2018-12-08 18:59:55 CET
Scala has a security issue that has been fixed upstream in 2.10.7:
https://nvd.nist.gov/vuln/detail/CVE-2017-15288

Mageia 6 is also affected.
David Walser 2018-12-08 19:00:01 CET

Whiteboard: (none) => MGA6TOO

David Walser 2019-02-03 02:46:33 CET

Status comment: (none) => Fixed upstream in 2.10.7

David Walser 2019-06-23 19:31:52 CEST

Whiteboard: MGA6TOO => MGA7TOO, MGA6TOO

Nicolas Lécureuil 2020-05-22 14:08:11 CEST

CC: (none) => mageia
Whiteboard: MGA7TOO, MGA6TOO => MGA7TOO

Comment 1 David Walser 2020-12-04 23:28:08 CET
*** Bug 27745 has been marked as a duplicate of this bug. ***

CC: (none) => zombie_ryushu

Zombie Ryushu 2020-12-21 11:19:14 CET

CVE: (none) => CVE-2017-15288

Comment 2 Nicolas Lécureuil 2021-01-04 11:40:00 CET
candidate to be obsoleted in mageia 8.
Comment 3 Nicolas Lécureuil 2021-01-06 20:14:34 CET
scala is removed from cauldron

Whiteboard: MGA7TOO => (none)
Version: Cauldron => 7

Comment 4 David Walser 2021-07-01 18:18:00 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Status: NEW => RESOLVED
Resolution: (none) => OLD