[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Security unfreezes/priority bumps



Neil McGovern wrote:
> Hi all,
> 
> Could I please have the following:
> gaim - priority bump 
> 	1:2.0.0+beta5-8 to 1:2.0.0+beta5-9
> 	no CVE ID yet, crash when receiving an invalid UPnP response

Unblocked by Marc

> libarchive - unfreeze
> 	1.2.53-2 to 1.3.1-1
> 	CVE-2006-5680 - DoS (CPU consumption)

Not important according to tracker and too big diff...

> nexuiz - unfreeze/bump
> 	2.1-1 to 2.2.1-1
> 	CVE-2006-6609 - DoS
> 	CVE-2006-6610 - remote console command injection
> nexuiz-data - unfreeze/bump
> 	2.1-1 to 2.2.1-1
> 	Same issues as above

Too big diff IMHO, so I'm not unblocking these...

> typo3-src - unfreeze
> 	4.0.2+debian-2 to 4.0.4+debian-1
> 	CVE-2006-6690 - arbitrary command execution

Fixed in 4.0.2+debian-2 according to the changelog (which I already approved).

Cheers

Luk

-- 
Luk Claes - http://people.debian.org/~luk - GPG key 1024D/9B7C328D
Fingerprint:   D5AF 25FB 316B 53BB 08E7   F999 E544 DE07 9B7C 328D

Attachment: signature.asc
Description: OpenPGP digital signature


Reply to: