Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.maint.java > #12350

Bug#700610: bsh (BeanShell) security vulnerability (CVE-2016-2510)

Path csiph.com!newsfeed.xs4all.nl!newsfeed9.news.xs4all.nl!bofh.it!news.nic.it!robomod
From Thorsten Glaser <t.glaser@tarent.de>
Newsgroups linux.debian.bugs.dist, linux.debian.maint.java
Subject Bug#700610: bsh (BeanShell) security vulnerability (CVE-2016-2510)
Date Wed, 23 Feb 2022 00:40:01 +0100
Message-ID <DTMLv-3FSS-3@gated-at.bofh.it> (permalink)
References <r3Scq-4Z3-7@gated-at.bofh.it> <r3TrP-5KW-3@gated-at.bofh.it> <r3VWG-7Ih-17@gated-at.bofh.it> <DTMit-3FsZ-15@gated-at.bofh.it> <kDpsR-n9-3@gated-at.bofh.it> <DTMit-3FsZ-15@gated-at.bofh.it>
X-Mailbox-Line From debian-bugs-dist-request@lists.debian.org Tue Feb 22 23:33:09 2022
Old-Return-Path <debbugs@buxtehude.debian.org>
X-Spam-Flag NO
X-Spam-Score -6.662
Reply-To Thorsten Glaser <t.glaser@tarent.de>, 700610@bugs.debian.org
Resent-To debian-bugs-dist@lists.debian.org
Resent-Cc Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
X-Debian-Pr-Message followup 700610
X-Debian-Pr-Package bsh
X-Debian-Pr-Source bsh
Content-Language de-DE-1901
MIME-Version 1.0
Content-Type text/plain; charset=UTF-8
Content-Transfer-Encoding QUOTED-PRINTABLE
X-Greylist delayed 507 seconds by postgrey-1.36 at buxtehude; Tue, 22 Feb 2022 23:30:02 UTC
X-Debian-Message from BTS
X-Mailing-List <debian-bugs-dist@lists.debian.org> archive/latest/1706376
List-ID <debian-bugs-dist.lists.debian.org>
List-URL <https://lists.debian.org/debian-bugs-dist/>
Approved robomod@news.nic.it
Lines 33
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Cc 700610@bugs.debian.org, debian-java@lists.debian.org
X-Original-Date Wed, 23 Feb 2022 00:21:24 +0100 (CET)
X-Original-Message-ID <9da89f6d-7b9d-5197-2b29-767a287bb7d@tarent.de>
X-Original-References <CAMBJEmU3hFuN4k7wrnhAgLtQxnCDH0joQO0A_9m=KXeJzA5xkQ@mail.gmail.com> <56C71965.6000101@apache.org> <CAMBJEmXuB7RtSK3JYR0jG1bD-VPRCTfq2nGnKW4PyKPn70aHdw@mail.gmail.com> <e38348c7-2927-6b43-e31e-7b95228c95ad@tu-dresden.de> <20130215085329.13065.37659.reportbug@rivest.cryptology.ch> <e38348c7-2927-6b43-e31e-7b95228c95ad@tu-dresden.de>
Xref csiph.com linux.debian.bugs.dist:1094293 linux.debian.maint.java:12350

Cross-posted to 2 groups.

Show key headers only | View raw


On Tue, 22 Feb 2022, Thomas Uhle wrote:

> What do you think, wouldn't it be time for an update in Debian?

The comment
> at https://github.com/beanshell/beanshell/issues/603 .
reads for me more like a “maybe remove it instead…”.

Honestly though, if it’s not available in Central, upstreams will
not use it and stick to old beta versions. If Debian has a newer
one, which may be incompatible, we’re inviting problems.

bye,
//mirabilos
-- 
Infrastrukturexperte • tarent solutions GmbH
Am Dickobskreuz 10, D-53121 Bonn • http://www.tarent.de/
Telephon +49 228 54881-393 • Fax: +49 228 54881-235
HRB AG Bonn 5168 • USt-ID (VAT): DE122264941
Geschäftsführer: Dr. Stefan Barth, Kai Ebenrett, Boris Esser, Alexander Steeg

                        ****************************************************
/⁀\ The UTF-8 Ribbon
╲ ╱ Campaign against      Mit dem tarent-Newsletter nichts mehr verpassen:
 ╳  HTML eMail! Also,     https://www.tarent.de/newsletter
╱ ╲ header encryption!
                        ****************************************************

Back to linux.debian.maint.java | Previous | NextPrevious in thread | Next in thread | Find similar


Thread

Bug#700610: bsh (BeanShell) security vulnerability (CVE-2016-2510) Thomas Uhle <thomas.uhle@mailbox.tu-dresden.de> - 2022-02-23 00:00 +0100
  Bug#700610: bsh (BeanShell) security vulnerability (CVE-2016-2510) Thorsten Glaser <t.glaser@tarent.de> - 2022-02-23 00:40 +0100
    Bug#700610: bsh (BeanShell) security vulnerability (CVE-2016-2510) Thomas Uhle <thomas.uhle@mailbox.tu-dresden.de> - 2022-02-25 22:40 +0100

csiph-web