[Pkg-clamav-devel] Bug#617444: clamav: (PRSC) Please backport fix for CVE-2011-1003

Adam D. Barratt adam at adam-barratt.org.uk
Tue Mar 15 17:04:51 UTC 2011


On Tue, March 15, 2011 13:17, Michael Tautschnig wrote:
>> Just to check: as far as I can see the SONAME hasn't changed in the new
>> upstream version, which is a good start :-) Are there any other API
>> changes which would mean we would need to rebuild any of the
>> reverse-dependencies in stable?
>>
>
> To the best of my knowledge, there aren't any changes that would affect
> the reverse depends. It's all internal bugfixes.

Thanks for the confirmation.

>> If not then please go ahead with the upload as 0.97+dfsg-2~squeeze1 -
>> assuming that the upload has been tested in that environment of course.
>
> Minimal testing of the squeeze-specific build has been performed; the same
> version, although built for lenny-volatile, is being "tested" in
> production environments. I'm now uploading to squeeze-updates.

Unfortunately, the upload got rejected by dak.

Please could you re-upload using "stable" as the distribution. 
"squeeze-updates" is not intended as a direct upload target.

>> Note that the versioning for the lenny-volatile upload originally used
>> -2~volatile1, which was higher than my request above.  As a result that
>> version will be adjusted to -2~lenny1 before it is released.
>>
>
> Yes, noted that one (and thanks Philipp Kern for fixing it without further
> hassle). Future uploads to lenny-volatile will follow these guidelines.

Thanks; that's appreciated.

Regards,

Adam






More information about the Pkg-clamav-devel mailing list