[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: jetty CVE triage: jetty8 ignored?



Hi Sebastien and others

I have checked a few of the CVEs from 2009 and my conclusion is that this is not important enough for LTS work.

CVE-2009-5045 to CVE-2009-5049 advisory sent by jetty telling that jetty 6 and 7 are affected. The version in jessie is of a version that is fixed. As jetty 8 did not exist at this time we can only assume that jetty designers themselves have fixed this. At the same time the affected apps are not shipped in the debian version.

CVE-2009-4612 was fixed a version long before the version in jessie. I do not think it is worth investigating jetty 8. If someone else feel you think this is important, please go ahead.

Other CVEs from 2009 have similar property. They were fixed in a version long before jessie was released. We do not have any specific patch pointer to them so investigating this would be quite time consuming.

As I said jetty seems to be a well maintained package where they themselves present advisories so I'm pretty comfortable with not investigating this on LTS time.

If you feel that this should be done, please go ahead. I will not stop you. Maybe someone else will but I will not.

Now let us focus on the issues we know are problems instead. That is definitely much more important!

Best regards

// Ola



On 6 July 2018 at 08:27, Sébastien Delafond <seb@debian.org> wrote:
On 2018-07-05, Ola Lundqvist <ola@inguza.com> wrote:
> If you read the mail chain you can see that I have alread analyzed the
> two CVEs. So it is already done.
>
> Is it so that you think we should reanalyze entries from 2009 as well,
> or?

Yes. All of them, not only the 2011 ones. Same for jetty 9 and CVEs
prior to 2015. Because relying on CVE year versus release date makes no
sense whatsoever.

Cheers,

--Seb




--
 --- Inguza Technology AB --- MSc in Information Technology ----
/  ola@inguza.com                    Folkebogatan 26            \
|  opal@debian.org                   654 68 KARLSTAD            |
|  http://inguza.com/                Mobile: +46 (0)70-332 1551 |
\  gpg/f.p.: 7090 A92B 18FE 7994 0C36 4FE4 18A1 B1CF 0FE5 3DD9  /
 ---------------------------------------------------------------


Reply to: