Bug#1057315: tiles: CVE-2023-49735

Moritz Muehlenhoff jmm at inutil.org
Sun Dec 3 14:10:53 GMT 2023


Salvatore Bonaccorso wrote:
> If you fix the vulnerability please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
> 
> The project is dead-upstream TTBOMK, so not sure if/what we can do at
> all for this issue. Removal seems not possible as per:
> 
> carnil at respighi:~$ dak rm --suite=unstable -n -R tiles
> Will remove the following packages from unstable:
> 
> libtiles-java |    3.0.7-5 | all
> libtiles-java-doc |    3.0.7-5 | all
>      tiles |    3.0.7-5 | source
> 
> Maintainer: Debian Java Maintainers <pkg-java-maintainers at lists.alioth.debian.org>
> 
> ------------------- Reason -------------------
> 
> ----------------------------------------------
> 
> Checking reverse dependencies...
> # Broken Build-Depends:
> libspring-java: libtiles-java (>= 3.0)
> 
> Dependency problem found.
> 
> carnil at respighi:~$
> 
> But maybe we can set it as "no-dsa", is it only used as build
> dependency for libspring-java and not sensible outside?

Spring is already marked as unsupported, so we can simply extend that.

Cheers,
        Moritz



More information about the pkg-java-maintainers mailing list