[Pkg-openldap-devel] planning another jessie upload

Luca BRUNO lucab at debian.org
Sat Feb 7 11:14:49 UTC 2015


Luciano Bello <luciano at debian.org> ha scritto:

> On Saturday 07 February 2015 06.52.19 Salvatore Bonaccorso wrote:
> > Just to avoid any problem: Wasn't the idea to release a fix for
> > #761406 trough a DSA? If yes, then I guess fixes for ##776988 and
> > #776991 could be squashed in in the planned update through
> > wheezy-security (but since Yves-Alexis is coordinating, this is only
> > a comment from my side, not wanting to interfering in current work
> > in progress).
> 
> Oh, I forgot about that thread. Sorry if I created confusion. I dont
> want to interfere with the work you have been done with Yves-Alexis,
> who is coordinating these issues.

No problem, we are actually piling up several old and new issues, so I
understand we may have generated some chaos. Sorry for that.

Just as a summary, we have the following known issues to be addressed:
 * #761406 (waiting on Yves-Alexis input)
 * #776988 (CVE requested by Ryan on oss-sec, pending)
 * #776991 (CVE requested by Ryan on oss-sec, pending)
 * #729367 (CVE-2013-4449, non-default module)

Cheers, Luca

-- 
  .''`.  |               ~<[ Luca BRUNO ~ (kaeso) ]>~
 : :'  : | Email: lucab (AT) debian.org ~ Debian Developer
 `. `'`  | GPG Key ID: 0x3BFB9FB3       ~ Free Software supporter
   `-    | HAM-radio callsign: IZ1WGT   ~ Networking sorcerer
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://lists.alioth.debian.org/pipermail/pkg-openldap-devel/attachments/20150207/fe9f574d/attachment.sig>


More information about the Pkg-openldap-devel mailing list