[
https://issues.apache.org/jira/browse/SPARK-18997?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15781139#comment-15781139
]
Sean Owen commented on SPARK-18997:
-----------------------------------
So, the questions are: does this CVE impact Spark at all? and what are the
other implications of updating like breaking changes?
A maintenance release is typically fine to take, but this is a very large one.
I'd like to see if the CVE even matters for Spark too -- can you provide more
info?
> Recommended upgrade libthrift to 0.9.3
> ---------------------------------------
>
> Key: SPARK-18997
> URL: https://issues.apache.org/jira/browse/SPARK-18997
> Project: Spark
> Issue Type: Bug
> Components: Build
> Reporter: meiyoula
> Priority: Critical
>
> libthrift 0.9.2 has a serious security vulnerability:CVE-2015-3254
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]