Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8de4f833 by Sylvain Beucler at 2021-04-14T18:52:04+02:00
CVE-2018-1271/libspring-java: fix reference

- - - - -
63d0c7e7 by Sylvain Beucler at 2021-04-14T18:57:16+02:00
CVE-2018-1257/libspring-java: precision

- - - - -
a3ee1e3a by Sylvain Beucler at 2021-04-14T19:03:30+02:00
CVE-2018-1272/libspring-java: drop copy/paste from unrelated CVE-2018-1270

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -214074,8 +214074,8 @@ CVE-2018-1273 (Spring Data Commons, versions prior to 
1.13 to 1.13.10, 2.0 to 2.
 CVE-2018-1272 (Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 
prior t ...)
        - libspring-java 4.3.19-1 (bug #895114)
        [stretch] - libspring-java <no-dsa> (Minor issue)
-       [jessie] - libspring-java <not-affected> (vulnerable code not found)
-       [wheezy] - libspring-java <not-affected> (Vulnerable broker code 
introduced in various commits re. 
https://github.com/spring-projects/spring-framework/blame/0009806debb578e884f6dc98bd1f2dc668020021/spring-messaging/src/main/java/org/springframework/messaging/simp/broker/DefaultSubscriptionRegistry.java)
+       [jessie] - libspring-java <no-dsa> (Minor issue)
+       [wheezy] - libspring-java <no-dsa> (Minor issue)
        NOTE: https://pivotal.io/security/cve-2018-1272
 CVE-2018-1271 (Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 
prior t ...)
        - libspring-java <not-affected> (Issue specific when served from a file 
system on Windows)
@@ -214083,8 +214083,9 @@ CVE-2018-1271 (Spring Framework, versions 5.0 prior 
to 5.0.5 and versions 4.3 pr
 CVE-2018-1270 (Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 
prior t ...)
        - libspring-java 4.3.19-1 (bug #895114)
        [stretch] - libspring-java <no-dsa> (Minor issue)
-       [jessie] - libspring-java <not-affected> (vulnerable code not found)
-       [wheezy] - libspring-java <not-affected> (Vulnerable broker code 
introduced in various commits re. 
https://github.com/spring-projects/spring-framework/blame/0009806debb578e884f6dc98bd1f2dc668020021/spring-messaging/src/main/java/org/springframework/messaging/simp/broker/DefaultSubscriptionRegistry.java)
+       [jessie] - libspring-java <not-affected> (Vulnerable code not present)
+       [wheezy] - libspring-java <not-affected> (Vulnerable code not present)
+       NOTE: Introduced by 
https://github.com/spring-projects/spring-framework/commit/b6327acec825aefadead62bd7825425b048b214c
 (v4.2.0)
        NOTE: https://pivotal.io/security/cve-2018-1270
        NOTE: when addressing this issue make sure to not only apply a partial 
fix but
        NOTE: make it complete, cf. 
https://bugzilla.redhat.com/show_bug.cgi?id=1565307
@@ -214117,8 +214118,9 @@ CVE-2018-1258 (Spring Framework version 5.0.5 when 
used in combination with any
 CVE-2018-1257 (Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x 
prior  ...)
        - libspring-java 4.3.19-1
        [stretch] - libspring-java <no-dsa> (Minor issue)
-       [jessie] - libspring-java <no-dsa> (hard to find upstream commits 
regarding this)
+       [jessie] - libspring-java <not-affected> (Vulnerable code introduced 
later)
        NOTE: https://pivotal.io/security/cve-2018-1257
+       NOTE: websocket introduced in v4 
https://github.com/spring-projects/spring-framework/commit/4e67f809fbc1957e40fc787686b63254eaa8d7fa
 CVE-2018-1256 (Spring Cloud SSO Connector, version 2.1.2, contains a 
regression which ...)
        NOT-FOR-US: Spring Cloud SSO Connector
 CVE-2018-1255 (RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 
7.1.0  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/644544b8bc31bf52d281e07c4f35a3041917331e...a3ee1e3ac7d0e96274b693b238f5e40f390bbc82

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/644544b8bc31bf52d281e07c4f35a3041917331e...a3ee1e3ac7d0e96274b693b238f5e40f390bbc82
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to