Thomas Gerbet (tgerbet)2017-08-23 15:43 RedHat position on this is won't fix [1]. The patch done by the more or less current maintainer [2] does not apply cleanly since the code he maintains has a bit diverged from what we have. Exploiting the vulnerability is hard with CVS especially in our context. Like the CVS RedHat distributes, the one in the Tuleap repository won't be fixed. [1] https://access.redhat.com/security/cve/cve-2017-12836 [2] https://www.mirbsd.org/permalinks/wlog-10_e20170811-tg.htm Status changed from Under implementation to DeclinedConnected artifacts Added Fixed in: rel #10571Close date set to 2017-08-23