[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Propose to ignore libxstream-java CVEs



Hi,

On 22/09/2021 15:37, Markus Koschany wrote:
so far I have not found any regressions in Debian packages which depend on
libxstream-java. I propose to switch to the whitelist in all suites because
this is the only reasonable way to secure XStream. I have prepared an update
for Stretch. Anton, could you take a look at it because I saw you have claimed
libxstream-java?

https://people.debian.org/~apo/lts/libxstream-java/libxstream-java.debdiff

I am pretty surprised because I had concluded that all reverse-dependencies would break, due to not white-listing any app-specific class:
https://lists.debian.org/debian-lts/2021/06/msg00040.html

I'll test your package shortly to see if my angle is relevant with this patch.

Cheers!
Sylvain Beucler
Debian LTS Team


Reply to: