Re: gradle / CVE-2019-11065

2019-05-08 Thread Brian May
Markus Koschany writes: > Gradle is a Java build tool and is mainly used to build Gradle based > packages for Debian. Since we build only with system libraries, this CVE > is only relevant for people who use our Gradle version to build > non-Debian packages. I assume not many people will do

Re: gradle / CVE-2019-11065

2019-05-07 Thread Markus Koschany
Hi, Am 07.05.19 um 09:40 schrieb Brian May: > Looking at Gradle in Jessie it looks like it has a number of http:// > URLS instead of https:// URLS that look dicy. > > There is this upstream patch that looks like it might be important and > also is missing from Jessie: > >