Overview

Request 798893 superseded

- Version update to 1.60 bsc#1100694:
* CVE-2018-1000613 Use of Externally-ControlledInput to Select Classes or Code
* Release notes:
http://www.bouncycastle.org/releasenotes.html

- Version update to 1.59:
* CVE-2017-13098: Fix against Bleichenbacher oracle when not
using the lightweight APIs (boo#1072697).
* Release notes:
http://www.bouncycastle.org/releasenotes.html
- Removed patch:
* ambiguous-reseed.patch

- Build with source and target 8 to prepare for a possible removal
of 1.6 compatibility


Pedro Monreal Gonzalez's avatar

Leap 15.0 was updated to version 1.60 but Leap 15.1 was still in 1.58.


Leap Reviewbot's avatar

home:pmonrealgonzalez:branches:openSUSE:Leap:15.1:Update/bouncycastle@3c550417a2c10c01ebd76e6ad87b0c61 -> openSUSE:Leap:15.1:Update/bouncycastle

expected origin is 'SUSE:SLE-15:GA' (changed)

Request History
Pedro Monreal Gonzalez's avatar

pmonrealgonzalez created request

- Version update to 1.60 bsc#1100694:
* CVE-2018-1000613 Use of Externally-ControlledInput to Select Classes or Code
* Release notes:
http://www.bouncycastle.org/releasenotes.html

- Version update to 1.59:
* CVE-2017-13098: Fix against Bleichenbacher oracle when not
using the lightweight APIs (boo#1072697).
* Release notes:
http://www.bouncycastle.org/releasenotes.html
- Removed patch:
* ambiguous-reseed.patch

- Build with source and target 8 to prepare for a possible removal
of 1.6 compatibility


Saul Goodman's avatar

licensedigger accepted review

ok


Factory Auto's avatar

factory-auto declined review

Output of check script:
ERROR: Failed to download "http://repo1.maven.org/maven2/org/bouncycastle/bcprov-jdk15on/1.60/bcprov-jdk15on-1.60.pom"
Source URLs are not valid. Try "osc service localrun download_files".


Factory Auto's avatar

factory-auto declined request

Output of check script:
ERROR: Failed to download "http://repo1.maven.org/maven2/org/bouncycastle/bcprov-jdk15on/1.60/bcprov-jdk15on-1.60.pom"
Source URLs are not valid. Try "osc service localrun download_files".


Pedro Monreal Gonzalez's avatar

pmonrealgonzalez superseded request

- Version update to 1.60 bsc#1100694:
* CVE-2018-1000613 Use of Externally-ControlledInput to Select Classes or Code
* Release notes:
http://www.bouncycastle.org/releasenotes.html

- Version update to 1.59:
* CVE-2017-13098: Fix against Bleichenbacher oracle when not
using the lightweight APIs (boo#1072697).
* Release notes:
http://www.bouncycastle.org/releasenotes.html
- Removed patch:
* ambiguous-reseed.patch

- Build with source and target 8 to prepare for a possible removal
of 1.6 compatibility

openSUSE Build Service is sponsored by