byte-buddy REMOVED from testing

2017-12-28 Thread Debian testing watch
FYI: The status of the byte-buddy source package in Debian's testing distribution has changed. Previous version: 1.7.2-1 Current version: (not in testing) Hint: Bug #882052: byte-buddy: missing build dependency on

libjtds-java 1.2.5+dfsg-4 MIGRATED to testing

2017-12-28 Thread Debian testing watch
FYI: The status of the libjtds-java source package in Debian's testing distribution has changed. Previous version: 1.2.5+dfsg-3 Current version: 1.2.5+dfsg-4 -- This email is automatically generated once a day. As the installation of new packages into testing happens multiple times a day

Bug#885576: undertow: CVE-2017-7559: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)

2017-12-28 Thread Markus Koschany
On Thu, 28 Dec 2017 09:55:12 +0100 Salvatore Bonaccorso wrote: > Source: undertow > Severity: important > Tags: security > > Hi, > > the following vulnerability was published for undertow. > > There is not much information available if that incomplete fix affects > us as

Bug#885577: libhibernate-validator-java: CVE-2017-7536: Privilege escalation when running under the security manager

2017-12-28 Thread Salvatore Bonaccorso
Source: libhibernate-validator-java Severity: important Tags: security Hi, the following vulnerability was published for libhibernate-validator-java. There is unfortunately not much information available, cf. [1]. CVE-2017-7536[0]: Privilege escalation when running under the security manager

Bug#885576: undertow: CVE-2017-7559: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)

2017-12-28 Thread Salvatore Bonaccorso
Source: undertow Severity: important Tags: security Hi, the following vulnerability was published for undertow. There is not much information available if that incomplete fix affects us as well. Or which this was fixed upstream. I asked for clarification in [1], but might you contact directly