[Pkg-libvirt-maintainers] Bug#623222: Bug#623222: CVE-2011-1486: Error handling not thread-safe

Guido Günther agx at sigxcpu.org
Fri Apr 29 19:17:22 UTC 2011


Hi Moritz,
On Wed, Apr 27, 2011 at 09:51:55PM +0200, Moritz Muehlenhoff wrote:
> Hi Guido,
> 
> > Just for the record: upstream's fix is in 0.9.0 already. 
> 
> Ok, I've updated the tracker.
> 
> > BTW Does tagging
> > the bugs as found/notfound update the affected versions at
> > 
> > https://bugzilla.redhat.com/show_bug.cgi?id=693391
> 
> We don't update the Red Hat bugzilla, no :-)

I figure you don't. C'n'p screwup, sorry.

> Did you mean http://security-tracker.debian.org/tracker/CVE-2011-1486 ?
Exactly.

> If you want to update version-specific entries (like "Squeeze is not
> affected, since the code isn't there yet") simply use
> http://security-tracker.debian.org/tracker/data/report

Great thanks!

> Alternatively we can also give you write access to the Debian Security
> Tracker as described here:
> http://svn.debian.org/wsvn/secure-testing/doc/narrative_introduction?op=file&rev=0&sc=0

I'll have a look.
Cheers,
 -- Guido





More information about the Pkg-libvirt-maintainers mailing list