batik: CVE-2019-17566

Related Vulnerabilities: CVE-2019-17566  

Debian Bug report logs - #964510
batik: CVE-2019-17566

version graph

Reported by: Emilio Pozuelo Monfort <pochu@debian.org>

Date: Wed, 8 Jul 2020 08:15:01 UTC

Severity: important

Tags: security

Found in version 1.8-4

Forwarded to https://issues.apache.org/jira/browse/BATIK-1276

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>:
Bug#964510; Package batik. (Wed, 08 Jul 2020 08:15:04 GMT) (full text, mbox, link).


Acknowledgement sent to Emilio Pozuelo Monfort <pochu@debian.org>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>. (Wed, 08 Jul 2020 08:15:04 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Emilio Pozuelo Monfort <pochu@debian.org>
To: submit@bugs.debian.org
Subject: batik: CVE-2019-17566
Date: Wed, 8 Jul 2020 10:10:56 +0200
Package: batik
X-Debbugs-CC: team@security.debian.org
Severity: important
Version: 1.8-4
Tags: security

Hi,

The following vulnerability was published for batik.

CVE-2019-17566[0]: SSRF vulnerability

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

Note that this is fixed upstream in 1.13, and the fix is easy to backport. You
may want to consider fixing this for buster and stretch via the upcoming point
release.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2019-17566
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17566

Please adjust the affected versions in the BTS as needed.



Set Bug forwarded-to-address to 'https://issues.apache.org/jira/browse/BATIK-1276'. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Wed, 08 Jul 2020 11:39:03 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Thu Jul 9 09:11:49 2020; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.