| Summary: | xstream new security issues CVE-2020-2625[89] | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | Java Stack Maintainers <java> |
| Status: | RESOLVED OLD | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | mageia, zombie_ryushu |
| Version: | 7 | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Source RPM: | xstream-1.4.14-1.mga8.src.rpm | CVE: | |
| Status comment: | Fixed upstream in 1.4.15 | ||
| Bug Depends on: | 28844 | ||
| Bug Blocks: | 27849 | ||
|
Description
David Walser
2020-12-29 16:29:11 CET
David Walser
2020-12-29 16:29:36 CET
Whiteboard:
(none) =>
MGA7TOO
David Walser
2020-12-29 16:29:49 CET
Blocks:
(none) =>
27849
David Walser
2020-12-29 17:31:07 CET
Status comment:
(none) =>
Fixed upstream in 1.4.15 version 1.4.15 pushed in cauldron Whiteboard:
MGA7TOO =>
(none) Debian-LTS has issued an advisory for this on December 31: https://www.debian.org/lts/security/2020/dla-2507 Debian has issued an advisory for this on January 7: https://www.debian.org/security/2021/dsa-4828 openSUSE has issued an advisory for this on January 22: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/CTO6QRFLVKVHOYBP6VLJP4KZXZFZSKET/
David Walser
2021-04-27 19:50:31 CEST
Depends on:
(none) =>
28844 https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/ Status:
NEW =>
RESOLVED |