Bug#1010154: libowasp-antisamy-java: CVE-2022-28366 + CVE-2022-28367

2022-04-26 Thread Neil Williams
On Mon, 25 Apr 2022 21:43:30 -0700 tony mancill wrote: > On Mon, Apr 25, 2022 at 07:22:12PM +0200, Salvatore Bonaccorso wrote: > > Hi! > > > > On Mon, Apr 25, 2022 at 01:48:43PM +0100, Neil Williams wrote: > > > On Mon, 25 Apr 2022 13:39:49 +0100 Neil Williams > > > wrote: > > > > Please note,

Bug#1010154: libowasp-antisamy-java: CVE-2022-28366 + CVE-2022-28367

2022-04-25 Thread tony mancill
On Mon, Apr 25, 2022 at 07:22:12PM +0200, Salvatore Bonaccorso wrote: > Hi! > > On Mon, Apr 25, 2022 at 01:48:43PM +0100, Neil Williams wrote: > > On Mon, 25 Apr 2022 13:39:49 +0100 Neil Williams > > wrote: > > > Please note, the current homepage for libowasp-antisamy-java appears to > > > have

Bug#1010154: libowasp-antisamy-java: CVE-2022-28366 + CVE-2022-28367

2022-04-25 Thread Salvatore Bonaccorso
Hi! On Mon, Apr 25, 2022 at 01:48:43PM +0100, Neil Williams wrote: > On Mon, 25 Apr 2022 13:39:49 +0100 Neil Williams wrote: > > Please note, the current homepage for libowasp-antisamy-java appears to > > have no commits beyond version 1.5.3 but the change for CVE-2022-29577 > > does match the

Bug#1010154: libowasp-antisamy-java: CVE-2022-28366 + CVE-2022-28367

2022-04-25 Thread Neil Williams
On Mon, 25 Apr 2022 13:39:49 +0100 Neil Williams wrote: > Please note, the current homepage for libowasp-antisamy-java appears to > have no commits beyond version 1.5.3 but the change for CVE-2022-29577 > does match the source code for libowasp-antisamy-java: >

Bug#1010154: libowasp-antisamy-java: CVE-2022-28366 + CVE-2022-28367

2022-04-25 Thread Neil Williams
Source: libowasp-antisamy-java Version: 1.5.3+dfsg-1.1 Severity: important Tags: security X-Debbugs-Cc: codeh...@debian.org, Debian Security Team Hi, Please note, the current homepage for libowasp-antisamy-java appears to have no commits beyond version 1.5.3 but the change for CVE-2022-29577