Bug#611138: CVE-2010-4438 / CVE-2011-5035

2012-05-14 Thread Steve McIntyre
On Mon, May 14, 2012 at 12:13:50AM +0200, Damien Raude-Morvan wrote: Hi all, Le dimanche 13 mai 2012 18:54:38, Steve McIntyre a écrit : Sadly, no :/ I must admit that Oracle does not publish details of its fixes so it's hard to confirm firmly what's component is exactly impacted. I'll try

Bug#611138: CVE-2010-4438

2012-05-13 Thread Steve McIntyre
On Wed, Jan 04, 2012 at 09:12:31PM +0100, Damien Raude-Morvan wrote: On 01/01/2012 19:47, Julien Cristau wrote: Hi, Hi Julien, On Wed, Jan 26, 2011 at 19:46:32 +0100, Damien Raude-Morvan wrote: So I don't think Debian package is affected by this issue, but we'll have to wait until

Bug#611138: CVE-2010-4438 / CVE-2011-5035

2012-05-13 Thread Damien Raude-Morvan
Hi all, Le dimanche 13 mai 2012 18:54:38, Steve McIntyre a écrit : Sadly, no :/ I must admit that Oracle does not publish details of its fixes so it's hard to confirm firmly what's component is exactly impacted. I'll try to revive my contact @Oracle to get some feedback on this issue (on

Bug#611138: CVE-2010-4438

2012-01-04 Thread Damien Raude-Morvan
On 01/01/2012 19:47, Julien Cristau wrote: Hi, Hi Julien, On Wed, Jan 26, 2011 at 19:46:32 +0100, Damien Raude-Morvan wrote: So I don't think Debian package is affected by this issue, but we'll have to wait until Oracle/Glassfish team publish some source code to confirm ths. Did that

Bug#611138: CVE-2010-4438

2012-01-01 Thread Julien Cristau
Hi, On Wed, Jan 26, 2011 at 19:46:32 +0100, Damien Raude-Morvan wrote: So I don't think Debian package is affected by this issue, but we'll have to wait until Oracle/Glassfish team publish some source code to confirm ths. Did that happen in the last year? Cheers, Julien __ This is the

Bug#611138: CVE-2010-4438

2011-01-26 Thread Damien Raude-Morvan
Hi, Le mardi 25 janvier 2011 23:02:18, Moritz Muehlenhoff a écrit : See http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4438 Please get in touch with Oracle to check, what unspecified vulnerability they fixed... From CVE abstract : Sun GlassFish Enterprise Server contains a flaw

Bug#611138: CVE-2010-4438

2011-01-26 Thread Moritz Mühlenhoff
On Wed, Jan 26, 2011 at 07:46:32PM +0100, Damien Raude-Morvan wrote: Hi, Le mardi 25 janvier 2011 23:02:18, Moritz Muehlenhoff a écrit : See http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4438 Please get in touch with Oracle to check, what unspecified vulnerability they

Bug#611138: CVE-2010-4438

2011-01-26 Thread Adam D. Barratt
user release.debian@packages.debian.org usertag 611138 + squeeze-can-defer tag 611138 + squeeze-ignore thanks On Wed, 2011-01-26 at 22:34 +0100, Moritz Mühlenhoff wrote: On Wed, Jan 26, 2011 at 07:46:32PM +0100, Damien Raude-Morvan wrote: So I don't think Debian package is affected by this

Processed: Re: Bug#611138: CVE-2010-4438

2011-01-26 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: user release.debian@packages.debian.org Setting user to release.debian@packages.debian.org (was a...@adam-barratt.org.uk). usertag 611138 + squeeze-can-defer Bug#611138: CVE-2010-4438 There were no usertags set. Usertags are now: squeeze

Bug#611138: CVE-2010-4438

2011-01-25 Thread Moritz Muehlenhoff
Package: glassfish Severity: grave Tags: security See http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4438 Please get in touch with Oracle to check, what unspecified vulnerability they fixed... Cheers, Moritz -- System Information: Debian Release: 6.0 APT prefers testing