[SECURITY] [DLA 2765-1] mupdf security update

2021-09-23 Thread Anton Gladky
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian LTS Advisory DLA-2765-1debian-...@lists.debian.org https://www.debian.org/lts/security/ Anton Gladky September 23, 2021

Accepted mupdf 1.14.0+ds1-4+deb9u1 (source) into oldoldstable

2021-09-23 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Thu, 23 Sep 2021 20:20:04 +0200 Source: mupdf Architecture: source Version: 1.14.0+ds1-4+deb9u1 Distribution: stretch-security Urgency: medium Maintainer: Kan-Ru Chen (陳侃如) Changed-By: Anton Gladky Changes: mupdf

Re: Propose to ignore libxstream-java CVEs

2021-09-23 Thread Anton Gladky
Hi Markus, I have applied your patch and the pipelines are passed [1]. So, at least nothing breaks from the "build side of view". Yes, I took this package, but uf your are working on it, feel free to reclaim it. [1] https://salsa.debian.org/lts-team/packages/libxstream-java/-/pipelines/292916

Re: Propose to ignore libxstream-java CVEs

2021-09-23 Thread Roberto C . Sánchez
On Thu, Sep 23, 2021 at 05:03:46PM +0200, Markus Koschany wrote: > > You are right that all applications will break which rely on the > deserialization feature of xstream and were not using a whitelist before. > Everything else that just writes a POJO to XML should be unaffected. In > general >

Re: Propose to ignore libxstream-java CVEs

2021-09-23 Thread Markus Koschany
Hi, Am Mittwoch, dem 22.09.2021 um 20:57 +0200 schrieb Sylvain Beucler: [...] > > > > I am pretty surprised because I had concluded that all reverse-dependencies > > would break, due to not white-listing any app-specific class: > > https://lists.debian.org/debian-lts/2021/06/msg00040.html > > >