[
https://issues.apache.org/jira/browse/SPARK-18997?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15791139#comment-15791139
]
Sean Owen commented on SPARK-18997:
-----------------------------------
Found the reference for this (this should be part of a JIRA like this when it's
reported):
http://grokbase.com/t/thrift/user/15c2tss3td/notice-apache-thrift-security-vulnerability-cve-2015-1774
It does seem like it could affect Spark. Can you open a PR? This still needs
some assessment of whether it could break anything.
> Recommended upgrade libthrift to 0.9.3
> ---------------------------------------
>
> Key: SPARK-18997
> URL: https://issues.apache.org/jira/browse/SPARK-18997
> Project: Spark
> Issue Type: Improvement
> Components: Build
> Reporter: meiyoula
> Priority: Minor
>
> libthrift 0.9.2 has a serious security vulnerability:CVE-2015-3254
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]