Re: [SECURITY] [DSA 532-1] New libapache-mod-ssl packages fix multiple vulnerabilities

On Thu, 22 Jul 2004 20:29:33 -0700
Matt Zimmerman <mdz@debian.org> wrote:
> Debian Security Advisory DSA 532-1                    
>          Matt Zimmerman
> July 22nd, 2004                        
> Package        : libapache-mod-ssl
> Vulnerability  : several
> Problem-Type   : remote
> Debian-specific: no
> CVE Ids        : CAN-2004-0488 CAN-2004-0700

> For the current stable distribution (woody), these problems have been
> fixed in version 2.8.9-2.3.

> We recommend that you update your libapache-mod-ssl package.
As the advisory recommended, I 'apt-get upgrade'd my stable boxen, but 
I noticed that on my alpha server the only thing that was updated where
the docs. Indeed the advisory doesn't talk about a new version
for alpha. Is there a reason why or did it just slip through? If there
is a reason maybe it would be good to mention it explicitly in the
advisory the next time it happens. That way people now if their box is
or is not vulnerable.

grts Tim 

