Processed: Re: Wheezy update of fop?

2017-04-26 Thread Debian Bug Tracking System
Processing control commands:

> forwarded -1 https://issues.apache.org/jira/browse/FOP-2668
Bug #860567 [src:fop] fop: CVE-2017-5661: information disclosure vulnerability
Set Bug forwarded-to-address to 
'https://issues.apache.org/jira/browse/FOP-2668'.

-- 
860567: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860567
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems

__
This is the maintainer address of Debian's Java team
. 
Please use
debian-j...@lists.debian.org for discussions and questions.


Re: Wheezy update of fop?

2017-04-26 Thread Mathieu Malaterre
Hi Ola,

On Sun, Apr 23, 2017 at 9:46 PM, Ola Lundqvist  wrote:
> Dear maintainer(s),
>
> The Debian LTS team would like to fix the security issues which are
> currently open in the Wheezy version of fop:
> https://security-tracker.debian.org/tracker/CVE-2017-5661
>
> Would you like to take care of this yourself?

The CVE is very unclear to me. It seems I need to upload fop 2.2 in
place of fop 2.1. Since we are in the middle of the freeze it does not
make much sense to make such upload in sid right now.

-M

__
This is the maintainer address of Debian's Java team
. 
Please use
debian-j...@lists.debian.org for discussions and questions.