[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Please remove libdevice-cdio-perl 0.2.4-1 from testing



Hi,

This is a new package I created a few days ago, it was NEW on the
20th. Yesterday I found and fixed a bug in memory allocation that
could trigger some memory corruption (and in my testing an immediate
abort). I think it's very unlikely to be a security problem, and if it
were, you should have to be fooled to download and open with this lib
a specially crafted ISO image (and the lib is not currently used by
any package in the archive).

But just in case I prepared an urgency=medium release, which was
promptly uploaded by Damyan Ivanov. I thought this would have been
enough to prevent the migration to testing, so I didn't file an RC bug
against it.

It seems that we weren't fast enough as the old version has just made
its way to testing. So, please remove it, the corrected version is
already in unstable.

Thanks.

-- 
Martín Ferrari



Reply to: