Bug#717031: libjgroups-java: CVE-2013-4112

Emmanuel Bourg ebourg at apache.org
Tue Jul 16 10:58:58 UTC 2013


Debian has JGroups 2.12, this version doesn't use authentication. An
attacker can disrupt a node (stopping or slowing it down) but not
execute arbitrary code.

Diagnostics are enabled by default. We can simply disable them by default.

Emmanuel Bourg



More information about the pkg-java-maintainers mailing list