[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#706142: tpu (or pu): telepathy-idle/0.1.11-2+deb7u1



user release.debian.org@packages.debian.org
usertag 706142 = pu
tag 706142 wheezy
kthxbye

On Thu, Apr 25, 2013 at 12:47:58 +0100, Simon McVittie wrote:

> Package: release.debian.org
> Severity: normal
> User: release.debian.org@packages.debian.org
> Usertags: unblock
> 
> The version of telepathy-idle in wheezy does not validate IRC servers'
> SSL certificates when used with SSL (#706094, CVE ID requested).
> 
> The version in sid was already newer than wheezy, so I uploaded the
> fixed upstream version there directly. For wheezy, I suggest a more minimal
> patch (attached) - this breaks a regression test which uses a pre-generated
> self-signed certificate, but we don't run those tests in Debian anyway.
> 
> Yves-Alexis Perez has indicated that this is not DSA material. Would you
> like me to upload to t-p-u before wheezy r0, or to s-p-u after r0 is out,
> or neither?

Too late for r0 IMO.

Cheers,
Julien

Attachment: signature.asc
Description: Digital signature


Reply to: