[Python-modules-team] Bug#673987: Bug#673987: CVE-2012-2374

Yaroslav Halchenko yoh at debian.org
Tue Jul 10 04:11:55 UTC 2012


as
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=673987#10
described, version in squeeze (1.0.1) is not effected and no action
should be done for current stable release.

or am I missing the point here?

On Mon, 09 Jul 2012, Jonathan Wiltshire wrote:

> Dear maintainer,

> Recently you fixed one or more security problems and as a result you closed
> this bug. These problems were not serious enough for a Debian Security
> Advisory, so they are now on my radar for fixing in the following suites
> through point releases:

> squeeze (6.0.6) - use target "stable"

> Please prepare a minimal-changes upload targetting each of these suites,
> and submit a debdiff to the Release Team [0] for consideration. They will
> offer additional guidance or instruct you to upload your package.

> I will happily assist you at any stage if the patch is straightforward and
> you need help. Please keep me in CC at all times so I can
> track [1] the progress of this request.

> For details of this process and the rationale, please see the original
> announcement [2] and my blog post [3].

> 0: debian-release at lists.debian.org
> 1: http://prsc.debian.net/tracker/673987/
> 2: <201101232332.11736.thijs at debian.org>
> 3: http://deb.li/prsc

> Thanks,

> with his security hat on:
-- 
Yaroslav O. Halchenko
Postdoctoral Fellow,   Department of Psychological and Brain Sciences
Dartmouth College, 419 Moore Hall, Hinman Box 6207, Hanover, NH 03755
Phone: +1 (603) 646-9834                       Fax: +1 (603) 646-1419
WWW:   http://www.linkedin.com/in/yarik        





More information about the Python-modules-team mailing list