On Thu, 7 May 2015, Raphael Hertzog wrote:
Altering the orig source might be OK but the upstream version should reflect that it has been altered by Debian. The convention we tend to use is to append "+ds" ("debian specific") and not inventing a fake ".1" sub-release.
But this wasn't a debian specific change. Everybody else who wants to have patches for these CVEs needs to add these binary files as well!?