[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: No tracker page for DSA-1940-1



Francesco Poli wrote:
> 
> The tracker page is now present, but there's a discrepancy that I would
> like to point out: the DSA claims that the issues are fixed in
> php5/5.2.11.dfsg.1-2 for sid and squeeze.
> However, the tracker (on the individual CVE pages) says that
> php5/5.2.11.dfsg.1-1 is fixed.
> By looking at the BTS bugs, it seems that this is true at least for
> CVE-2009-2626 and CVE-2009-2687, but there's no indication that this
> should be the case for CVE-2009-3291 and CVE-2009-3292...

Some of the issues were previously fixed in unstable (in -1), and the
{old,}stable uploads addressed those and the temporary files exhaustion
vuln.

Cheers,
-- 
Raphael Geissert - Debian Developer
www.debian.org - get.debian.net



Reply to: