[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: DSA-2000-1 vs. tracker



On Fri, 19 Feb 2010 17:10:41 -0500 Michael Gilbert wrote:

[...]
> the problems are very likely solved, but there's no evidence either way
> yet that i've seen.  i would rather see them tested before declaring
> them done

I can understand your need for additional evidence.

Nonetheless, the problem is still that we have an inconsistency here:
the DSA claims that sid is fixed, while the tracker says that sid is
still vulnerable.

As I said, I hope that relevant facts have been verified, before
stating them in an official DSA.
If this is not the case, I hope that they are verified real soon now
and, if necessary, an updated DSA is issued.

On the other hand, if the checks have already been performed by Moritz,
or by someone else, I don't see a reason to not update the tracker
accordingly.


-- 
 http://www.inventati.org/frx/progs/scripts/pdebuild-hooks.html
 Need some pdebuild hook scripts?
..................................................... Francesco Poli .
 GnuPG key fpr == C979 F34B 27CE 5CD8 DC12  31B5 78F4 279B DD6D FCF4

Attachment: pgp_ovCEbkdB8.pgp
Description: PGP signature


Reply to: