• Bug#1108864: [discussion] unblock: libpgjava/42.7.7-1

    From Salvatore Bonaccorso@21:1/5 to All on Sun Jul 6 15:50:01 2025
    XPost: linux.debian.devel.release

    Package: release.debian.org
    Severity: normal
    X-Debbugs-Cc: [email protected], Christoph Berg <[email protected]>, [email protected], [email protected]
    Control: affects -1 + src:libpgjava
    User: [email protected]
    Usertags: unblock

    Hi Christoph,

    libpgjava cannot migrate from unstable to testing as it is considered
    a key package. The changes between 42.7.5-2 and 42.7.7-1 contain in
    particular the fix for CVE-2025-49146.

    Can you comment to the release team if you consider the package ready
    and suitable to be able to migrate? If not, how can CVE-2025-49146 be
    addressed for trixie?

    TTBOMK, libpgjava updates in stable have been done by following the
    respetive upstream branch including the fixes.

    Regards,
    Salvatore

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Christoph Berg@21:1/5 to All on Mon Jul 7 14:20:01 2025
    XPost: linux.debian.devel.release

    Re: Salvatore Bonaccorso
    libpgjava cannot migrate from unstable to testing as it is considered
    a key package. The changes between 42.7.5-2 and 42.7.7-1 contain in particular the fix for CVE-2025-49146.

    Can you comment to the release team if you consider the package ready
    and suitable to be able to migrate? If not, how can CVE-2025-49146 be addressed for trixie?

    I think it would be appropriate for trixie. It's been out for a while
    and I haven't heard of complaints.

    Christoph

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)