[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: icedove: security issue - already fixed?



you don't need to, and you probably shouldn't retroactively update the
changelog.  we don't base the tracker off of changelog entries anyway
since that isn't reliable.

mike

On Thu, Sep 2, 2010 at 1:15 PM, Christoph Goehre wrote:
> Hi Hideki,
>
> On Thu, Sep 02, 2010 at 07:16:17PM +0900, Hideki Yamane wrote:
>> Hi icedove maintainer,
>>
>>  Now I'm checking security-tracker and there still two security bug flags
>>  that releated to icedove package exist.
>>  http://security-tracker.debian.org/tracker/CVE-2010-1196
>>  http://security-tracker.debian.org/tracker/CVE-2010-1199
>>
>>  There is no mention in its changelog for
>>
>>   - MFSA 2010-25 aka CVE-2010-1121
>>      http://www.mozilla.org/security/announce/2010/mfsa2010-25.html
>>   - MFSA 2010-26 aka CVE-2010-1200, CVE-2010-1201 and CVE-2010-1202
>>      http://www.mozilla.org/security/announce/2010/mfsa2010-26.html
>>   - MFSA 2010-29 aka CVE-2010-1196
>>      http://www.mozilla.org/security/announce/2010/mfsa2010-29.html
>>   - MFSA 2010-30 aka CVE-2010-1199
>>      http://www.mozilla.org/security/announce/2010/mfsa2010-30.html
>>
>>  however, those issue were already fixed with this 3.0.5 release, right?
>>  If so, please add it to its changelog next upload.
>
> sorry, I've missed that. It will be fixed in my next upload.
>
> BTW: It's just a little bit stupid, because Mozilla release a new
> version but announce the fixes security issues mostly one day later.
>
> Cheers,
> Christoph
>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.10 (GNU/Linux)
>
> iQIcBAEBCAAGBQJMf9uPAAoJECbjyHWnRCDvzzIP/Av22ZLOfWWix6WI+CPBnJN5
> IbR3kgMC5UKZMq/x3RMjlnQMmLLHUJbG6PdRFip/BugZZQ7S/Kxc0Jk+1Z2gwYOW
> QIEKRa9lelhRcJJ3PExNLRIddwwsHz654+4IweRWOE+qDICdVeU3cgAd0z8EH4Fr
> w42wMY8Kl5Bu9VnrCQn0bunFpBE90VRuLZXeQwFz8sImv+HkOCedwUn/4d9SYJVk
> wpB5NoGeBL9hznLMonH6ttVVIlFLmLhvPNZsNku5dx7YSLQrd3qjJ/dy2pJY3/Cs
> VXloA2ED6WFZL3C6lnK3qz1oVHTJs48Jbt2KcQYdCrmv69WFS4QnQbMXdlJ8RD5P
> YLSBZ8eTLy23QU5XNwDy+M07AE85+a/GLI8P2GP2uRr18b0C3i1yd5Jiqh13ZkvA
> Hbh+N3VimQ/2RA5bGmza7GXbYlhsy7j1P/FHifGqdPyGwoXOApJQY97Z3pF/NVJ5
> YbPAmtAXXPOQ50gPo7JteWRKCrMorcBeiibE981CErv/C8WhV9ERXiw4WPrEUNPU
> LglJphplM5X9eQj7oz8m8rfvcldUszy8beI4kngVub8nhJuFM1c5n521BRrtWAsK
> wRpACQf3ht0WLmGDlCChDRC3yFxIFfMK/56P7skXw9Cuv4I6cgsnU/0ifgJtf2ut
> uClTtFcpT2wtjY6CeWN6
> =16p0
> -----END PGP SIGNATURE-----
>
>


Reply to: