[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2018-1271/libspring-java: fix reference

Sylvain Beucler beuc at debian.org
Wed Apr 14 18:15:23 BST 2021



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8de4f833 by Sylvain Beucler at 2021-04-14T18:52:04+02:00
CVE-2018-1271/libspring-java: fix reference

- - - - -
63d0c7e7 by Sylvain Beucler at 2021-04-14T18:57:16+02:00
CVE-2018-1257/libspring-java: precision

- - - - -
a3ee1e3a by Sylvain Beucler at 2021-04-14T19:03:30+02:00
CVE-2018-1272/libspring-java: drop copy/paste from unrelated CVE-2018-1270

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -214074,8 +214074,8 @@ CVE-2018-1273 (Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.
 CVE-2018-1272 (Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...)
 	- libspring-java 4.3.19-1 (bug #895114)
 	[stretch] - libspring-java <no-dsa> (Minor issue)
-	[jessie] - libspring-java <not-affected> (vulnerable code not found)
-	[wheezy] - libspring-java <not-affected> (Vulnerable broker code introduced in various commits re. https://github.com/spring-projects/spring-framework/blame/0009806debb578e884f6dc98bd1f2dc668020021/spring-messaging/src/main/java/org/springframework/messaging/simp/broker/DefaultSubscriptionRegistry.java)
+	[jessie] - libspring-java <no-dsa> (Minor issue)
+	[wheezy] - libspring-java <no-dsa> (Minor issue)
 	NOTE: https://pivotal.io/security/cve-2018-1272
 CVE-2018-1271 (Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...)
 	- libspring-java <not-affected> (Issue specific when served from a file system on Windows)
@@ -214083,8 +214083,9 @@ CVE-2018-1271 (Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 pr
 CVE-2018-1270 (Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...)
 	- libspring-java 4.3.19-1 (bug #895114)
 	[stretch] - libspring-java <no-dsa> (Minor issue)
-	[jessie] - libspring-java <not-affected> (vulnerable code not found)
-	[wheezy] - libspring-java <not-affected> (Vulnerable broker code introduced in various commits re. https://github.com/spring-projects/spring-framework/blame/0009806debb578e884f6dc98bd1f2dc668020021/spring-messaging/src/main/java/org/springframework/messaging/simp/broker/DefaultSubscriptionRegistry.java)
+	[jessie] - libspring-java <not-affected> (Vulnerable code not present)
+	[wheezy] - libspring-java <not-affected> (Vulnerable code not present)
+	NOTE: Introduced by https://github.com/spring-projects/spring-framework/commit/b6327acec825aefadead62bd7825425b048b214c (v4.2.0)
 	NOTE: https://pivotal.io/security/cve-2018-1270
 	NOTE: when addressing this issue make sure to not only apply a partial fix but
 	NOTE: make it complete, cf. https://bugzilla.redhat.com/show_bug.cgi?id=1565307
@@ -214117,8 +214118,9 @@ CVE-2018-1258 (Spring Framework version 5.0.5 when used in combination with any
 CVE-2018-1257 (Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior  ...)
 	- libspring-java 4.3.19-1
 	[stretch] - libspring-java <no-dsa> (Minor issue)
-	[jessie] - libspring-java <no-dsa> (hard to find upstream commits regarding this)
+	[jessie] - libspring-java <not-affected> (Vulnerable code introduced later)
 	NOTE: https://pivotal.io/security/cve-2018-1257
+	NOTE: websocket introduced in v4 https://github.com/spring-projects/spring-framework/commit/4e67f809fbc1957e40fc787686b63254eaa8d7fa
 CVE-2018-1256 (Spring Cloud SSO Connector, version 2.1.2, contains a regression which ...)
 	NOT-FOR-US: Spring Cloud SSO Connector
 CVE-2018-1255 (RSA Identity Lifecycle and Governance versions 7.0.1, 7.0.2 and 7.1.0  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/644544b8bc31bf52d281e07c4f35a3041917331e...a3ee1e3ac7d0e96274b693b238f5e40f390bbc82

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/644544b8bc31bf52d281e07c4f35a3041917331e...a3ee1e3ac7d0e96274b693b238f5e40f390bbc82
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210414/caf5ee0b/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list