[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: suggestions for packages to force to testing for security fixes



On Wed, Mar 30, 2005 at 09:06:39PM -1000, Joey Hess wrote:
> Packages that have a security fix blocked by arm only:

> ltris 1.0.6-1.1 needed, have 1.0.6-1 for CAN-2005-0825 
> racoon 1:0.5-5 needed, have 0.3.3-7 for CAN-2005-0398 

Force hints (but not force-hint hints) added.  Feel free to do these
yourself, y'know. :)

> Packages that are blocked by arm and m68k:

> epiphany-browser 1.4.8-2 needed, have 1.4.7-3 for CAN-2005-0238 

Also pushed in because m68k has been uploaded; otherwise I would've waited.

> lsh-utils 2.0-1 needed, have 1.4.2-8.2 for CAN-2005-0389
> lsh-utils 2.0.1-1 needed, have 1.4.2-8.2 for CAN-2005-0814 
> 	(Also has a RC bug though.)

yeah, that doesn't sound like a win yet (though it's also built on m68k).

> smail 3.2.0.115-7 needed, have 3.2.0.115-5.1 for CAN-2005-0892 
> 	(The RC bug 301428 should not block this fix from sarge.)

Also pushed in, now that it's built on m68k and I've had a chance to look at
301428.

> Packages that are frozen:

> netkit-telnet 0.17-28 needed, have 0.17-26 for DSA-697-1
> 	0.17-27 consisted of misc other changes, but
> 	0.17-28 only fixed the security hole (which is quite a bad one)

0.17-29 is tentatively approved; still needs to age and get built
everywhere.

-- 
Steve Langasek
postmodern programmer

Attachment: signature.asc
Description: Digital signature


Reply to: