[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: #506353 CVE-2008-5312/3: mailscanner might allow local users to overwrite arbitrary files via a symlink attack



On Monday 2008 December 15 15:16:31 Simon Walter wrote:
>Is there a chance to get 4.74.8 unblocked?

Yes.  The release team has final say, but I think they are generally amenable 
to requests from the maintainer or a DD with a new package ready.

>Is it very unwise to even 
>try so? 

No, but do your best to make sure it does not introduce any bugs.  Also, make 
sure it doesn't break any dependencies on your binary package(s) for packages 
already in Lenny.

>Do I have to contact security team and work on a fix for 
>4.68.8?

That's what I would pursue.  4.68.8-1lenny1 would be a good version for a 
security update.  After the package is in stable, that will be the way 
forward for security updates (or other fixes for high-severity bugs) so you 
might as well get used to it now.
-- 
Boyd Stephen Smith Jr.                     ,= ,-_-. =. 
bss03@volumehost.net                      ((_/)o o(\_))
ICQ: 514984 YM/AIM: DaTwinkDaddy           `-'(. .)`-' 
http://iguanasuicide.org/                      \_/     

Attachment: signature.asc
Description: This is a digitally signed message part.


Reply to: