Your message dated Mon, 24 Mar 2014 21:24:03 +0000
with message-id <e1wsclj-00062h...@franck.debian.org>
and subject line Bug#741604: fixed in libspring-java 3.0.6.RELEASE-13
has caused the Debian Bug report #741604,
regarding libspring-java: Multiple security issues
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
741604: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=741604
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: libspring-java
Severity: grave
Tags: security
Justification: user security hole
http://www.gopivotal.com/security/cve-2014-0054
http://www.gopivotal.com/security/cve-2014-1904
I'm not sure whether these are worth a DSA?
Cheers,
Moritz
--- End Message ---
--- Begin Message ---
Source: libspring-java
Source-Version: 3.0.6.RELEASE-13
We believe that the bug you reported is fixed in the latest version of
libspring-java, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 741...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Miguel Landaeta <nomad...@debian.org> (supplier of updated libspring-java
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Mon, 24 Mar 2014 17:10:32 -0300
Source: libspring-java
Binary: libspring-core-java libspring-beans-java libspring-aop-java
libspring-context-java libspring-context-support-java libspring-web-java
libspring-web-servlet-java libspring-web-struts-java libspring-web-portlet-java
libspring-test-java libspring-transaction-java libspring-jdbc-java
libspring-jms-java libspring-orm-java libspring-expression-java
libspring-oxm-java libspring-instrument-java
Architecture: source all
Version: 3.0.6.RELEASE-13
Distribution: unstable
Urgency: high
Maintainer: Debian Java Maintainers
<pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: Miguel Landaeta <nomad...@debian.org>
Description:
libspring-aop-java - modular Java/J2EE application framework - AOP
libspring-beans-java - modular Java/J2EE application framework - Beans
libspring-context-java - modular Java/J2EE application framework - Context
libspring-context-support-java - modular Java/J2EE application framework -
Context Support
libspring-core-java - modular Java/J2EE application framework - Core
libspring-expression-java - modular Java/J2EE application framework -
Expression language
libspring-instrument-java - modular Java/J2EE application framework -
Instrumentation
libspring-jdbc-java - modular Java/J2EE application framework - JDBC tools
libspring-jms-java - modular Java/J2EE application framework - JMS tools
libspring-orm-java - modular Java/J2EE application framework - ORM tools
libspring-oxm-java - modular Java/J2EE application framework - Object/XML
Mapping
libspring-test-java - modular Java/J2EE application framework - Test helpers
libspring-transaction-java - modular Java/J2EE application framework -
transaction
libspring-web-java - modular Java/J2EE application framework - Web
libspring-web-portlet-java - modular Java/J2EE application framework - Portlet
MVC
libspring-web-servlet-java - modular Java/J2EE application framework - Web
Portlet
libspring-web-struts-java - modular Java/J2EE application framework - Struts
MVC
Closes: 741604
Changes:
libspring-java (3.0.6.RELEASE-13) unstable; urgency=high
.
* Fix CVE-2014-0054 and CVE-2014-1904. (Closes: #741604).
Checksums-Sha1:
b24faaedacb3c0350133a35c8c6ec85d87f020ab 4487
libspring-java_3.0.6.RELEASE-13.dsc
7c22298e4be3ccebcd0155c86dc5de4d904831ce 26492
libspring-java_3.0.6.RELEASE-13.debian.tar.xz
8fbbe8da235423de64e4e7dd828fb95599891a2f 362994
libspring-core-java_3.0.6.RELEASE-13_all.deb
6eeb3780b7c92256afb5ef20d15d7cc09353232d 516742
libspring-beans-java_3.0.6.RELEASE-13_all.deb
d350883f7314f49b917c49dfdf1bfd07c6eaa995 327234
libspring-aop-java_3.0.6.RELEASE-13_all.deb
7c484b7742cc016fb3a32ec0d49bc581da6a0734 590472
libspring-context-java_3.0.6.RELEASE-13_all.deb
0730ef3701f2133f5082f39b0ead2eb742ee3844 113432
libspring-context-support-java_3.0.6.RELEASE-13_all.deb
dfb78e7556cd2584682b118857b34c985e1900f2 370752
libspring-web-java_3.0.6.RELEASE-13_all.deb
94228c43d839895f8173a3ea52576d994f9ef6d7 396816
libspring-web-servlet-java_3.0.6.RELEASE-13_all.deb
dd29744dd3a12ac5fca683d7b31d18df315ad077 52158
libspring-web-struts-java_3.0.6.RELEASE-13_all.deb
c2529aefa83bc01fb0b4585e4b067befa16a179f 179726
libspring-web-portlet-java_3.0.6.RELEASE-13_all.deb
1dfacb1c2cbc678d882129d674270adf094cef27 204110
libspring-test-java_3.0.6.RELEASE-13_all.deb
65b6af63e5137238a1f2db0d4506bbe67064db18 211492
libspring-transaction-java_3.0.6.RELEASE-13_all.deb
94032e73690e82fd39dd6126c8174c629119adef 356704
libspring-jdbc-java_3.0.6.RELEASE-13_all.deb
63db695d5c10f6a75eaf20f30e27664c5b53d899 186168
libspring-jms-java_3.0.6.RELEASE-13_all.deb
02d001e08a08529b9aff7f9e6a930669ff1da475 315106
libspring-orm-java_3.0.6.RELEASE-13_all.deb
bc3e443a5cb7a45cc9c7bd9f3928c02f3b4073d2 176446
libspring-expression-java_3.0.6.RELEASE-13_all.deb
a2fce6b2b5f5595de73a65870712b9c2663cbcf7 79046
libspring-oxm-java_3.0.6.RELEASE-13_all.deb
90219bda50adfad35dda84cf0d876d6783a9b871 30474
libspring-instrument-java_3.0.6.RELEASE-13_all.deb
Checksums-Sha256:
dc2079e51c89137fd0705ccc783c8d730adc12583455a53161d6836540e36b19 4487
libspring-java_3.0.6.RELEASE-13.dsc
7a43227449439ee36da6aded8ce64edda1a8326b0740baa1f4545135a6dd57af 26492
libspring-java_3.0.6.RELEASE-13.debian.tar.xz
a51abcbf5ed55e14b53f4771ee9093221d8655d9bec77d0d4f1741783a8ebe1d 362994
libspring-core-java_3.0.6.RELEASE-13_all.deb
a3e22014a9fa8fbe482ec1feaa1c8eb1e6aada4340c029a7a1f68f4fe3c1cbaf 516742
libspring-beans-java_3.0.6.RELEASE-13_all.deb
ab768a072f976ad9ce3114ff3528311e7a260f205d5c19d89a584bce9a7f1097 327234
libspring-aop-java_3.0.6.RELEASE-13_all.deb
c080240d5f9cc20a70861e892aead565bb2bba78964fc953ae2f2507f85a00ed 590472
libspring-context-java_3.0.6.RELEASE-13_all.deb
16d4e3e32f15eac9025898556ba43f8cf36114161e9042f66c4f2a06935b54ea 113432
libspring-context-support-java_3.0.6.RELEASE-13_all.deb
5a0b01bd33098ddcc6e409d52da7fc7dd52ca33c6a3cc6c76f0cb0719d346011 370752
libspring-web-java_3.0.6.RELEASE-13_all.deb
8cecabc4597c87829da0769298d4311f3c961e92156f6d33f3a4a3b3185be9db 396816
libspring-web-servlet-java_3.0.6.RELEASE-13_all.deb
1a33a7762932694ec8d6cb9b10787a6f611d3d2e0e14f4d9226334f587d601fc 52158
libspring-web-struts-java_3.0.6.RELEASE-13_all.deb
68463282832b3bcd8d8bb8ae666d8c51592bc06db0dffcb43a37e4dda2bbc9c5 179726
libspring-web-portlet-java_3.0.6.RELEASE-13_all.deb
3496aafda887fd10521199b84f13c3893fcd69a9be2de1fcdd6d07c640845e0f 204110
libspring-test-java_3.0.6.RELEASE-13_all.deb
47e862cb44bf6d42c2cd54b8c83e5e76e829341ad00d092e9e339a2f27e48318 211492
libspring-transaction-java_3.0.6.RELEASE-13_all.deb
0f063129be26301473518a73d597d305ef5313671c258dd4fc2a0d9ad6debee9 356704
libspring-jdbc-java_3.0.6.RELEASE-13_all.deb
e65024020916b84b1439bc633d12df995ba25565b1315f219fae9246784e63a0 186168
libspring-jms-java_3.0.6.RELEASE-13_all.deb
52a10f0981144589ffc35cd243f6ebe35b08e74842dbe2daebaadd0b79316fa3 315106
libspring-orm-java_3.0.6.RELEASE-13_all.deb
f60c4bc45dfe0202ab203c21d20442ef1276703f989b6a2c7700070225d8368d 176446
libspring-expression-java_3.0.6.RELEASE-13_all.deb
899157a8ecdb4df8061af730588bead6d6c10f3d790818673b1ce4bdc2e803e5 79046
libspring-oxm-java_3.0.6.RELEASE-13_all.deb
f8a5ab47768e584f90271653788def0946e4fb6e11f89d7dd855162036145365 30474
libspring-instrument-java_3.0.6.RELEASE-13_all.deb
Files:
959c7816fb205caa925269a6da263f2a 4487 java extra
libspring-java_3.0.6.RELEASE-13.dsc
c56375c0f30426a9057a5307d1a21ab0 26492 java extra
libspring-java_3.0.6.RELEASE-13.debian.tar.xz
1e6530feb511556b4e00b334c3d24621 362994 java extra
libspring-core-java_3.0.6.RELEASE-13_all.deb
6ce3064eb42686d6e737641d2f33d1cd 516742 java extra
libspring-beans-java_3.0.6.RELEASE-13_all.deb
11409875ce85e8a9fd2b8a166002b079 327234 java extra
libspring-aop-java_3.0.6.RELEASE-13_all.deb
137e033cbbe3b3566947348f008a8a64 590472 java extra
libspring-context-java_3.0.6.RELEASE-13_all.deb
f376c85f3e9578ce314ec5d389abb959 113432 java extra
libspring-context-support-java_3.0.6.RELEASE-13_all.deb
adca0656e627ff347942170f3f76ca77 370752 java extra
libspring-web-java_3.0.6.RELEASE-13_all.deb
09ab52c9182c76aef1da28b3b5adaeb3 396816 java extra
libspring-web-servlet-java_3.0.6.RELEASE-13_all.deb
85db9e923a4e13cc40d2d400838076b9 52158 java extra
libspring-web-struts-java_3.0.6.RELEASE-13_all.deb
92a5968920adb4d77ac0aad1197c6922 179726 java extra
libspring-web-portlet-java_3.0.6.RELEASE-13_all.deb
280f4636744427cb9a5772f70818d534 204110 java extra
libspring-test-java_3.0.6.RELEASE-13_all.deb
0efc76bd3123cec3b5958ba5f1031df8 211492 java extra
libspring-transaction-java_3.0.6.RELEASE-13_all.deb
81ecdbc7013e3b5343ecc3135e2103ba 356704 java extra
libspring-jdbc-java_3.0.6.RELEASE-13_all.deb
eb665f447081ff475351fbc5ae480308 186168 java extra
libspring-jms-java_3.0.6.RELEASE-13_all.deb
55d2364bafac147c648f66117f9e30c6 315106 java extra
libspring-orm-java_3.0.6.RELEASE-13_all.deb
7c1d80b1b2642f0ba73f66a0b89018e0 176446 java extra
libspring-expression-java_3.0.6.RELEASE-13_all.deb
8dfebbc6747547afd702a58fdf89ec68 79046 java extra
libspring-oxm-java_3.0.6.RELEASE-13_all.deb
79e32bcd89edd39d0a375976dfd5295f 30474 java extra
libspring-instrument-java_3.0.6.RELEASE-13_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQIcBAEBAgAGBQJTMJq9AAoJEI8AS/UHtGj7n/gQAKcZalg8vdo9eokYkk3xbqc1
nmqlifeMguxdynq/3WMudXICJPzitWlsw1Zv0lwnoXnj4hVj8IHEjIJhQ+mdGbTr
iymgRFy0g0JOEU2L6F6Wnuf/LEGId2MuXPc5weiIdWukKeHpAEhdVWQ4lTpqRzH9
t5blBIlgisbp7vrPX+hyCvPdzxGxDjL7a9O2P4WzZrFbx+mpDlaL2qb7iFSizU82
fihhfEdw8ZVRUeCDnDCUStBRgEiHN8G9kfpoN+EcgBwxBtkPWzs2+ePIQA6NXKhC
fY9R6/YC9FoyWwO3U26eRGsU+rZTDt2gy8Q2SzLitVNPbhMWueIc7Gk1ngOs+hGQ
tTddm9txPqG+42LxARLMpXIAE0kt+facePkD/YTQLfrR9Bd/P/BQBuQTJRNlVtAn
hIAT2cA429kf5Suw245OFSNkzsgsVjZHHeXSVJcffEA7i97FKEpCymTzzQ/CHtHi
Qz95LpeO2EFgjG+fx7QARfIJRStTXYyFmiBxwtixZsp3pzjlzJnFSwlJXn8SKN/5
25NReDcXmA5/gcDWjMo51NKhVDdvPxHMNbbX0gcqxRf+WiXsQfT8aDss1X0cbzl4
MpUEUZRL5qMubRllY9dUk8ykZAmP4f9FuO/VuqPE77nfKRW2a8xyviX0RlV8QZXK
4Se8KKAh4QwxkIAKhptT
=i3/Q
-----END PGP SIGNATURE-----
--- End Message ---
__
This is the maintainer address of Debian's Java team
<http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-java-maintainers>.
Please use
debian-j...@lists.debian.org for discussions and questions.