[Pkg-zsh-devel] Multiple vulnerabilities in stable zsh package?

Yves-Alexis Perez corsac at debian.org
Fri Sep 28 07:18:40 BST 2018


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Thu, 2018-09-27 at 19:09 -0600, Nathan Dorfman wrote:
> Hello,
> 
> It seems that the stable version of the zsh package (5.3.1-4) might be
> vulnerable to quite a few security issues:

Hi Nathan,

you can see the security status of zsh here:

https://security-tracker.debian.org/tracker/source-package/zsh

Basically all the issues have been marked as unimportant or no-dsa. They might
qualify for a stable update but it's up to the maintainers to request that
from the release team.

Regards,
- -- 
Yves-Alexis
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEE8vi34Qgfo83x35gF3rYcyPpXRFsFAlutx8AACgkQ3rYcyPpX
RFtYrgf/WMNHB4FY+MUqGDESSDgKNrRypqHK9fAHhS41kLKbVTC/CrGQlD8qKqNK
30gKd3s/1LYQkPIpaEsOIzpYVhQ1lUWH3GT3bFxXoRr+KJuI20K3J86lXIIXgZ/6
3vpT8N9ghnpWWSBi3KW9EBEu9cz76NzLA7a/YW8M9reUNmjbmfpzViEBWHZcBWdg
sabVWP0Mef7ish+rZeDh3Ov8ElWSfNtuik2LMvbvD7htcdKfv4iNPFFlhRaMlXMe
S37uapY71tQOEbthgZsM6lrlBQXJcZisBeltPr7CjGZtEyyr2t12/MKIrOqD1jmn
7H0GDspSz4w5uv9S9p+FWJ2OmGfy7A==
=hrnM
-----END PGP SIGNATURE-----



More information about the Pkg-zsh-devel mailing list