[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Please unblock moodle-1.8.2-2



* Francois Marier <francois@debian.org> [2008-11-17 02:22:39 CET]:
> Please note that the package is no longer orphaned and now has a committed
> maintenance team behind it.

 Is that committed maintenance team (would be kind to get informations
who that team is, too - more out of curiosity about size or if those
people might really be actively interested) additionally to maintaining
the package also interested in the point that was brought up at the
start of october by Thijs:

| There are many more open security issues in stable:
| http://security-tracker.debian.net/tracker/source-package/moodle

 I just extracted the outstanding issues in stable that could need a
helping hand (hope I didn't miss any):
http://security-tracker.debian.net/tracker/CVE-2007-3555
http://security-tracker.debian.net/tracker/CVE-2008-1502
http://security-tracker.debian.net/tracker/CVE-2008-3325
http://security-tracker.debian.net/tracker/CVE-2008-3326
http://security-tracker.debian.net/tracker/CVE-2008-4796
http://security-tracker.debian.net/tracker/CVE-2008-4810
http://security-tracker.debian.net/tracker/CVE-2008-4811

 Furthermore, moodle does have aside from smarty also other embedded
code copies that should had get addressed a long time ago already,
what's your plan about that?

 Thanks for your efforts anyway,
Rhonda


Reply to: