[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: (pre-approval) unblock: trafficserver/5.0.1-1+deb8u1



Hi,

On Tuesday 10 March 2015 17:27:04 Arnaud Fontaine wrote:
> Ok, before  uploading and filing a  proper unblock request, I  will wait
> for the maintainer ACK until Friday if that's ok with you.

I'm fine with your NMU, but please note it's only part of the problem. We never 
bothered for the (easy) fix for #778895 because of other security problems we 
cannot easily fix in particular CVE-2014-3624 and #749846 - both fixed in Sid.

However, the Release Team was uncomfortable to unblock that package (cf. 
#769689). I'm afraid, that we better ask for removal of that package in 
Testing rather than bothering with it, as we - as maintainers - cannot 
guarantee for the security of it already, even less so over the lifespan of a 
Debian Release, and upstream is moving faster than us. 

-- 
with kind regards,
Arno Töll
IRC: daemonkeeper on Freenode/OFTC
GnuPG Key-ID: 0x9D80F36D

Attachment: signature.asc
Description: This is a digitally signed message part.


Reply to: