Hi Luke, If the package isn't vulnerable, shouldn't this bug report be closed? If that's the case, then I'll let you close it. In the mean while, I'll downgrade the severity to normal, in order to not remove the package (and its rev-dependencies) from testing. Cheers, Thomas Goirand (zigo)