Hi Ola, On 11/13/17 20:15, Ola Lundqvist wrote: > You are right two of the issues are not an issue in wheezy. I have > marked them accordingly. However one remains. I did not find time to > look through the last ome. I have already looked at that, it is present. But please see my comments in bug 881110¹ about how to treat it. I have, in the process of this, also filed bug 1072 upstream (about CVE-2009-4112). I think that until there is a patch for CVE-2009-4112, one can ignore fixing CVE-2017-16641. However, please read the upstream bug 1072 about the potential progress. Paul ¹ https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881110 ² https://github.com/Cacti/cacti/issues/1072
Attachment:
signature.asc
Description: OpenPGP digital signature