Bug#952683: snakeyaml: CVE-2017-18640

2020-03-26 Thread Salvatore Bonaccorso
Hello Tony, On Wed, Mar 25, 2020 at 10:04:47PM -0700, tony mancill wrote: > Hello Salvatore, > > On Sat, Feb 29, 2020 at 09:17:50PM +0100, Salvatore Bonaccorso wrote: > > > The upstream issue has been marked as resolved and the links to the > > > proposed resolution returns a 404. I agree that

Bug#952683: snakeyaml: CVE-2017-18640

2020-03-25 Thread tony mancill
Hello Salvatore, On Sat, Feb 29, 2020 at 09:17:50PM +0100, Salvatore Bonaccorso wrote: > > The upstream issue has been marked as resolved and the links to the > > proposed resolution returns a 404. I agree that we should have an issue > > open in the tracker, but I don't see how this is

Bug#952683: snakeyaml: CVE-2017-18640

2020-02-29 Thread Salvatore Bonaccorso
Hi Tony, On Sat, Feb 29, 2020 at 09:51:32AM -0800, tony mancill wrote: > On Thu, Feb 27, 2020 at 03:16:00PM +0100, Salvatore Bonaccorso wrote: > > Source: snakeyaml > > Version: 1.25+ds-2 > > Severity: important > > Tags: security upstream > > Forwarded:

Bug#952683: snakeyaml: CVE-2017-18640

2020-02-29 Thread tony mancill
On Thu, Feb 27, 2020 at 03:16:00PM +0100, Salvatore Bonaccorso wrote: > Source: snakeyaml > Version: 1.25+ds-2 > Severity: important > Tags: security upstream > Forwarded: https://bitbucket.org/asomov/snakeyaml/issues/377 > Control: found -1 1.23-1 > Control: found -1 1.17-1 > > Hi, > > The

Bug#952683: snakeyaml: CVE-2017-18640

2020-02-27 Thread Salvatore Bonaccorso
Source: snakeyaml Version: 1.25+ds-2 Severity: important Tags: security upstream Forwarded: https://bitbucket.org/asomov/snakeyaml/issues/377 Control: found -1 1.23-1 Control: found -1 1.17-1 Hi, The following vulnerability was published for snakeyaml. CVE-2017-18640[0]: | The Alias feature in