commit:     f5987ec362a8eac13d17db3fc29306ac0f5be4d7
Author:     Volkmar W. Pogatzki <gentoo <AT> pogatzki <DOT> net>
AuthorDate: Tue Jun  6 07:22:59 2023 +0000
Commit:     Miroslav Šulc <fordfrog <AT> gentoo <DOT> org>
CommitDate: Wed Jun  7 05:23:16 2023 +0000
URL:        https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f5987ec3

profiles: Last rite dev-java/janino, CVE-2023-33546

Bug: https://bugs.gentoo.org/907927
Signed-off-by: Volkmar W. Pogatzki <gentoo <AT> pogatzki.net>
Closes: https://github.com/gentoo/gentoo/pull/31329
Signed-off-by: Miroslav Šulc <fordfrog <AT> gentoo.org>

 profiles/package.mask | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/profiles/package.mask b/profiles/package.mask
index 3b6064df9c99..86efe8de552e 100644
--- a/profiles/package.mask
+++ b/profiles/package.mask
@@ -33,6 +33,15 @@
 
 #--- END OF EXAMPLES ---
 
+# Volkmar W. Pogatzki <[email protected]> (2023-06-06)
+# Vulnerable CVE-2023-33546, Bug #907927.
+# Reverse deps (logback-*, netty) are unused Java libraries.
+# Removal on 2023-07-06.
+dev-java/janino
+dev-java/logback-core
+dev-java/logback-classic
+dev-java/netty
+
 # Sam James <[email protected]> (2023-06-06)
 # Causes "illegal instruction" (SIGILL) errors for some users, pending 
investigation.
 # See bug #907932.

Reply via email to