[Debian-astro-maintainers] Bug#949188: starjava-topcat: Please remove unneeded build-dependency on libxmlrpc3-client-java
Markus Koschany
apo at debian.org
Fri Jan 17 22:42:54 GMT 2020
Source: starjava-topcat
Version: 4.7-1
Severity: important
Hi,
please remove the build-dependency on libxmlrpc3-client-java because
libxmlrpc3-java is EOL, no longer supported by upstream, affected by
CVE-2019-17570 and should be removed from Debian. starjava-topcat is
the only reverse-dependency. It appears you can safely remove the
build-dependency because it is not needed to build your package.
Regards,
Markus
More information about the Debian-astro-maintainers
mailing list