Bug#777196: activemq: CVE-2014-8110 CVE-2014-3612 CVE-2014-3600

2015-02-17 Thread Moritz Muehlenhoff
On Fri, Feb 06, 2015 at 01:56:35PM +0100, Emmanuel Bourg wrote: For CVE-2014-3600: https://github.com/apache/activemq/commit/b9696ac8 https://issues.apache.org/jira/browse/AMQ-5333 Could you please upload a fixed package for CVE-2014-3612 and CVE-2014-3600? Cheers, Moritz __ This is

Bug#777196: activemq: CVE-2014-8110 CVE-2014-3612 CVE-2014-3600

2015-02-06 Thread Emmanuel Bourg
Here is the commit to backport for CVE-2014-3612: https://github.com/apache/activemq/commit/0b5231ad https://issues.apache.org/jira/browse/AMQ-5345 I'm looking for the others. __ This is the maintainer address of Debian's Java team

Bug#777196: activemq: CVE-2014-8110 CVE-2014-3612 CVE-2014-3600

2015-02-06 Thread Emmanuel Bourg
For CVE-2014-3600: https://github.com/apache/activemq/commit/b9696ac8 https://issues.apache.org/jira/browse/AMQ-5333 and CVE-2014-8110: https://github.com/apache/activemq/commit/994d9b26 https://issues.apache.org/jira/browse/AMQ-5033 But I don't think the console is packaged, I couldn't find

Bug#777196: activemq: CVE-2014-8110 CVE-2014-3612 CVE-2014-3600

2015-02-05 Thread Moritz Muehlenhoff
Package: activemq Severity: important Tags: security Hi, please see http://activemq.apache.org/security-advisories.data/CVE-2014-8110-announcement.txt (but the admin console isn't enabled, so this should be moot? (702670))