<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<html lang="en">
<head>
<meta content="text/html; charset=US-ASCII" http-equiv="Content-Type">
<title>
GitLab
</title>



<style>img {
max-width: 100%; height: auto;
}
</style>
</head>
<body>
<div class="content">

<h3>
Markus Koschany pushed to branch master
at <a href="https://salsa.debian.org/security-tracker-team/security-tracker">Debian Security Tracker / security-tracker</a>
</h3>
<h4>
Commits:
</h4>
<ul>
<li>
<strong><a href="https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a7b197cfe7c6f5e331a9aec3e9d44f163ce54734">a7b197cf</a></strong>
<div>
<span>by Markus Koschany</span>
<i>at 2021-10-02T20:24:14+02:00</i>
</div>
<pre class="commit-message" style="white-space: pre-wrap; margin: 0;">CVE-2021-35515,CVE-2021-35516,CVE-2021-35517,CVE-2021-36090,libcommons-compress-java

Add fixing commits. I have tried to contact the Apache Commons security team
but I have not received any feedback yet. The information about the security
fixes have been removed from

https://commons.apache.org/proper/commons-compress/security-reports.html

and there is a bug report for it already.

https://issues.apache.org/jira/browse/COMPRESS-586

However using the Wayback Machine I could find the removed information and
use them now as documentation for the security tracker.

https://web.archive.org/web/20210713041119/https://commons.apache.org/proper/commons-compress/security-reports.html

The changes are rather intrusive. A targeted backport would require some
serious effort. Although, we could also backport the new upstream release 1.21.
Apache Commons releases are very stable according to Emmanuel Bourg who is also
a committer for commons-compress. Since the vulnerabilities are of low severity
it is also acceptable to mark them as no-dsa.
</pre>
</li>
</ul>
<h4>1 changed file:</h4>
<ul>
<li class="file-stats">
<a href="#4716ef5aa8f2742228ba3b3633215c8b808565e3">
data/CVE/list
</a>
</li>
</ul>
<h4>Changes:</h4>
<li id="4716ef5aa8f2742228ba3b3633215c8b808565e3">
<a href="https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a7b197cfe7c6f5e331a9aec3e9d44f163ce54734#4716ef5aa8f2742228ba3b3633215c8b808565e3"><strong>data/CVE/list</strong></a>
<hr>
No preview for this file type
<br>
</li>

</div>
<div class="footer" style="margin-top: 10px;">
<p style="font-size: small; color: #666;">

<br>
<a href="https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a7b197cfe7c6f5e331a9aec3e9d44f163ce54734">View it on GitLab</a>.
<br>
You're receiving this email because of your account on salsa.debian.org.
If you'd like to receive fewer emails, you can
adjust your notification settings.
<script type="application/ld+json">{"@context":"http://schema.org","@type":"EmailMessage","action":{"@type":"ViewAction","name":"View Commit","url":"https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a7b197cfe7c6f5e331a9aec3e9d44f163ce54734"}}</script>


</p>
</div>
</body>
</html>