[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Propose to ignore libxstream-java CVEs



Hi all,

so far I have not found any regressions in Debian packages which depend on
libxstream-java. I propose to switch to the whitelist in all suites because
this is the only reasonable way to secure XStream. I have prepared an update
for Stretch. Anton, could you take a look at it because I saw you have claimed
libxstream-java?

https://people.debian.org/~apo/lts/libxstream-java/libxstream-java.debdiff


Regards,

Markus





Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: