Re: Bug#505563: Mozilla Thunderbird Multiple Vulnerabilities


While I can understand your position. This still leaves an RC bug open against lenny.

What do you propose we do for lenny?

1. Leave bug open for lenny. Tag lenny-ignore?

2. Request freeze exception for the new upstream release?

3. Other?


From: Mike Hommey <mh@glandium.org>
Date: 31/12/2008 17:56

On Wed, Dec 31, 2008 at 04:21:05PM +1100, Mark Purcell wrote:
> Thanks Alexander,
> Be advised that the normal approach to fixing a RC bug during lenny deep freeze is by back porting the fix, rather than uploading the new upstream release.
> Have debian-release been engaged?

We (the mozilla team) don't have the resources nor the time to cherry
pick security fixes for mozilla packages. Other people are welcome to
join if they wish to do that, but so far, nobody volunteered.


