[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

About the security issues affecting fex in Squeeze



Hello Kilian,

the Debian LTS team recently reviewed the security issue(s) affecting your
package in Squeeze:
https://security-tracker.debian.org/tracker/TEMP-0000000-AD275E
https://security-tracker.debian.org/tracker/source-package/fex

We decided that we would not prepare a squeeze security update (usually
because the security impact is low and that we concentrate our limited
resources on higher severity issues and on the most widely used packages).
That said the squeeze users would most certainly benefit from a fixed
package.

BTW contrary to what you said in
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=773751#5 this is the
only open security issue in squeeze, the others have been fixed by Thorsten
Alteholz in version 20100208+debian1-1+squeeze4, see
https://packages.qa.debian.org/f/fex/news/20140930T180401Z.html

If you want to work on such an update, you're welcome to do so. Please
try to follow the workflow we have defined here:
http://wiki.debian.org/LTS/Development

If that workflow is a burden to you, feel free to just prepare an
updated source package and send it to debian-lts@lists.debian.org
(via a debdiff, or with an URL pointing to the the source package,
or even with a pointer to your packaging repository), and the members
of the LTS team will take care of the rest. However please make sure to
submit a tested package.

Thank you very much.

Raphaël Hertzog,
  on behalf of the Debian LTS team.
-- 
Raphaël Hertzog ◈ Debian Developer

Support Debian LTS: http://www.freexian.com/services/debian-lts.html
Learn to master Debian: http://debian-handbook.info/get/


Reply to: