[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: WebGUI and Debian Squeeze



On 07/10/2010 16:39, Ernesto Hernández-Novich wrote:
> 
> It will take me a couple of days before I either upload 7.8.24-2 (hi 
> gregoa!) or ask for webgui's removal from Squeeze.

Well, I think that there is point in waiting for a couple of days.

In a previous mail, you wrote:

On 07/09/2010 04:50, Ernesto Hernández-Novich wrote:
> There have been several _potential_ security issues in all the 7.x 
> releases before 7.9 that have been addressed and fixed but cannot be 
> backported to 7.8 because of structural changes in WebGUI. That's one 
> of the reasons why an upgrade to 7.9 is mandatory. Colin has offered to
> grant access to the bug reports that show the potential vulnerabilities
> and explain the fact that they can't be backported to 7.8.

Now, we won't accept 7.9, and 7.8 seems unfixable according to your own words.
If we discover new unfixable security issues during Squeeze's lifetime,
what would we do? Removing it from Squeeze *now* looks to me like the best
option.

Regards,

-- 
Mehdi Dogguy مهدي الدڤي
mehdi@{dogguy.org,debian.org}


Reply to: