Hi, Am 10.11.18 um 13:38 schrieb Abhijith PA: > Hello. > > > What we should do when we miss to specify a CVE ID in a DLA/DSA ? Can we > just normally insert in next advisory release.? For eg: DLA-478-1[1] > released for squid3 on 16 May 2016 missed to mention 'CVE-2016-3948'. You can add the missing CVE entry to data/DLA/list manually and you also have to mark CVE-2016-3948 as fixed by DLA-478-1 like that {DLA-478-1}. Markus
Attachment:
signature.asc
Description: OpenPGP digital signature