Commits on Source (11)
-
Emmanuel Bourg authored76df0b74
-
Emmanuel Bourg authored95b820d2
-
Emmanuel Bourg authoredbb24ae81
-
Emmanuel Bourg authored9967d154
-
Markus Koschany authored3278dfe0
-
Markus Koschany authoredde050fc9
-
Markus Koschany authoredb615b58b
-
Markus Koschany authored4a9cb30a
-
Markus Koschany authored
jackson-databind (2.4.2-2+deb8u3) jessie-security; urgency=high * Team upload. * Fix CVE-2017-17485 and CVE-2018-5968: Bybass of deserialization blackist to disallow unauthenticated remote code execution. These CVE exist due to an incomplete fix for CVE-2017-7525. (Closes: #888316, #888318) jackson-databind (2.4.2-2+deb8u2) jessie-security; urgency=high * Team upload * CVE-2017-15095: incomplete fixes for CVE-2017-7525
6740cafd -
Markus Koschany authored2bf099f1
-
Markus Koschany authored3062d842
debian/gbp.conf
0 → 100644
debian/patches/CVE-2017-15095_1.patch
0 → 100644
debian/patches/CVE-2017-15095_2.patch
0 → 100644
debian/patches/CVE-2017-15095_3.patch
0 → 100644
debian/patches/CVE-2017-17485.patch
0 → 100644
debian/patches/CVE-2018-5968.patch
0 → 100644
debian/patches/CVE-2018-7489.patch
0 → 100644