On Thu, Nov 30, 2006 at 06:41:21AM -0500, Thomas Dickey wrote:
> > Changes: 
> >  lynx (2.8.5-2sarge2.2) unstable; urgency=low
> >  .
> >    * Non-maintainer upload.
> >    * Read user configuration from home directory, not current
> >      working directory. Closes: #396964
> >      Thanks to Tom Parker for the patch.
> 
> There's no possibility of including that patch upstream.
So what? If upstream does not want to accept a patch that fixes a
security bug (which #396964 is, if I read it correctly), that's their
problem. Debian often releases packages with patches that are not
accepted by upstream, for various reasons.
-- 
Met vriendelijke groet / with kind regards,
      Guus Sliepen <guus@debian.org>
Attachment:
signature.asc
Description: Digital signature