squeeze update of libspring-2.5-java?

Raphael Hertzog hertzog at debian.org
Mon Mar 9 14:18:35 UTC 2015


Hello Emmanuel,

On Tue, 24 Feb 2015, Emmanuel Bourg wrote:
> CVE-2011-3923 seems to be a Struts vulnerability, why is it assigned to
> Spring?

I asked Salvatore Bonaccorso <carnil at debian.org> to review this since
he confirmed that assignation a while ago... he double checked and
it was a mistake (the CVE assignation has been fixed now).

Cheers,
-- 
Raphaël Hertzog ◈ Debian Developer

Support Debian LTS: http://www.freexian.com/services/debian-lts.html
Learn to master Debian: http://debian-handbook.info/get/



More information about the pkg-java-maintainers mailing list