[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: jessie RC bugs in perl packages



On Sat, 20 May 2017 13:21:12 +0300, Adrian Bunk wrote:

> I'm adding the release team to the Cc for the 3 bugs that are
> candidates for jessie-ignore.

Thanks!
 
> > > #849777 shutter: CVE-2016-10081: Insecure use of perl exec()
> > 
> > I'm confused. This should be fixed in 0.92-0.1+deb8u1.
> > At least that's what https://tracker.debian.org/news/829114 says.
> > Still, https://bugs.debian.org/849777 doesn't know about it?
> >...
> 
> CVE-2015-0854 != CVE-2016-10081

Oops :/
Sorry, I should I have stopped yesterday when I realized that I was
getting tired.

Done now: cherrypicked the same commits for stable in git and filed a
pu bug.


Cheers,
gregor

-- 
 .''`.  https://info.comodo.priv.at/ - Debian Developer https://www.debian.org
 : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D  85FA BB3A 6801 8649 AA06
 `. `'  Member of VIBE!AT & SPI, fellow of the Free Software Foundation Europe
   `-   

Attachment: signature.asc
Description: Digital Signature


Reply to: