Subject: Rare project developers
List archive
- From: Alexander Gall <>
- To: mc36 <>
- Cc: Xavier Jeannin <>, "" <>
- Subject: Re: [rare-dev] bulk upgrade of the rare packages
- Date: Fri, 22 Jul 2022 14:54:02 +0200
On Fri, 22 Jul 2022 14:37:00 +0200, mc36 <> said:
> On 7/22/22 14:21, Alexander Gall wrote:
>>
>>> so it was a missing emptyness check in the very core of ec signature
>>> verification,
>>> affecting everything that uses that... most notably the tls handshake is
>>> the most
>>> prominent example, but everything that does an ec verify operation is
>>> affected...
>>
>> CVE-2022-21449 appears to not affect OpenJDK 14 (what we currently
>> use) according to
>> https://openjdk.org/groups/vulnerability/advisories/2022-04-19. Can
>> you confirm this?
>>
> unfortunately i cannot.. jdk14 was never intended to be an lts, that is, it
> never got an update
Yeah, but the bug only appeared in 15, so can't be in 14, right?
Anyway, I'm making you an offer in another part of this thread.
--
Alex
- Re: [rare-dev] bulk upgrade of the rare packages, (continued)
- Re: [rare-dev] bulk upgrade of the rare packages, Alexander Gall, 07/22/2022
- Re: [rare-dev] bulk upgrade of the rare packages, mc36, 07/22/2022
- Re: [rare-dev] bulk upgrade of the rare packages, mc36, 07/22/2022
- Re: [rare-dev] bulk upgrade of the rare packages, Alexander Gall, 07/22/2022
- Re: [rare-dev] bulk upgrade of the rare packages, mc36, 07/22/2022
- Re: [rare-dev] bulk upgrade of the rare packages, mc36, 07/22/2022
- Re: [rare-dev] bulk upgrade of the rare packages, Alexander Gall, 07/27/2022
- Re: [rare-dev] bulk upgrade of the rare packages, mc36, 07/27/2022
- Re: [rare-dev] bulk upgrade of the rare packages, Alexander Gall, 07/29/2022
- Re: [rare-dev] bulk upgrade of the rare packages, mc36, 07/29/2022
- Re: [rare-dev] bulk upgrade of the rare packages, Alexander Gall, 07/22/2022
- Re: [rare-dev] bulk upgrade of the rare packages, mc36, 07/22/2022
- Re: [rare-dev] bulk upgrade of the rare packages, mc36, 07/22/2022
- Re: [rare-dev] bulk upgrade of the rare packages, Alexander Gall, 07/22/2022
- Re: [rare-dev] bulk upgrade of the rare packages, mc36, 07/22/2022
Archive powered by MHonArc 2.6.19.