[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#768321: unblock: curl/7.38.0-3



On Thu, Nov 06, 2014 at 05:04:38PM +0100, Niels Thykier wrote:
> Control: tags -1 confirmed
> 
> On Thu, 06 Nov 2014 14:46:59 +0100 Alessandro Ghedini <ghedo@debian.org>
> wrote:
> > Package: release.debian.org
> > Severity: normal
> > User: release.debian.org@packages.debian.org
> > Usertags: unblock
> > 
> > Hello,
> > 
> > I'd like to upload curl 7.38.0-3 which contains a patch for CVE-2014-3707. This
> > will also contain an additional change that enables all hardening build flags,
> > which, AFAICT, isn't included in the approved changes categories, but given the
> > 6 curl CVEs in the last 12 months, I think it'd be a good idea to have in
> > jessie.
> > 
> > Here's the changelog:
> > 
> >  curl (7.38.0-3) unstable; urgency=high
> >  .
> >    * Enable all hardening options (Closes: #763372)
> >    * [...]
> > 
> > and the debdiff is attached.
> > 
> > Can I go on and upload the package?
> > 
> > Thanks
> > 
> > [...]
> 
> Hi,
> 
> We are willing to accept the proposed debdiff.  One remark, the
> hardening change is accepted as an exception; normally I would have
> rejected that (but cURL ought to have it - thus, the exception).
> 
> Please let us know when it is accepted in unstable.

Uploaded and accepted.

Cheers

Attachment: signature.asc
Description: Digital signature


Reply to: