libhibernate-validator-java: status change on tests.reproducible-builds.org/debian

2019-07-30 Thread Reproducible builds folks
2019-07-31 00:15 https://tests.reproducible-builds.org/debian/unstable/amd64/libhibernate-validator-java changed from FTBR -> FTBFS __ This is the maintainer address of Debian's Java team . Please use

Bug#933393: jackson-databind: CVE-2019-14439 CVE-2019-14379

2019-07-30 Thread Salvatore Bonaccorso
Control: retitle -1 jackson-databind: CVE-2019-14439 CVE-2019-14379 There seem to have been a confusion around the CVE to be assigned for https://github.com/FasterXML/jackson-databind/issues/2389 . Whilst the subject contains still CVE-2019-14361 the right CVE looks to be CVE-2019-14439 according

Processed: Re: Bug#933393: jackson-databind: CVE-2019-14439 CVE-2019-14379

2019-07-30 Thread Debian Bug Tracking System
Processing control commands: > retitle -1 jackson-databind: CVE-2019-14439 CVE-2019-14379 Bug #933393 [src:jackson-databind] jackson-databind: CVE-2019-14361 CVE-2019-14379 Changed Bug title to 'jackson-databind: CVE-2019-14439 CVE-2019-14379' from 'jackson-databind: CVE-2019-14361

Bug#933393: jackson-databind: CVE-2019-14361 CVE-2019-14379

2019-07-30 Thread Salvatore Bonaccorso
Source: jackson-databind Version: 2.9.8-3 Severity: grave Tags: security upstream Justification: user security hole Hi, The following vulnerabilities were published for jackson-databind. CVE-2019-14361[0]: | block logback/jndi CVE-2019-14379[1]: | SubTypeValidator.java in FasterXML