[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: libxfont1 issues should not show up in the latently vulnerable packages list



Hi Florian,
* Florian Weimer <fw@deneb.enyo.de> [2008-07-06 17:25]:
> * Nico Golde:
> > Looking at the underlying tracker data the problem seems to 
> > be that DSA-1466-2 included an upload for libxfont for the 
> > above CVE ids while only CVE-2008-0006 was fixed in the 
> > update of libxfont. Also only CVE-2008-0006 applies to the 
> > package in testing/unstable.
> 
> A workaround is to copy the libxfont annotation to the CVE/list file and
> remove it from the DSA/list file.

Thanks, done.
Cheers
Nico
-- 
Nico Golde - http://www.ngolde.de - nion@jabber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgp4F4wAPDx0u.pgp
Description: PGP signature


Reply to: