[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [SECURITY] [DSA 875-1] New OpenSSL packages fix cryptographic weakness



joey@infodrom.org (Martin Schulze) wrote:

> The following matrix explains which version in which distribution has
> this problem corrected.
>
>                 oldstable (woody)      stable (sarge)     unstable (sid)
> openssl          0.9.6c-2.woody.8       0.9.7e-3sarge1      0.9.8-3
> openssl 094      0.9.4-6.woody.4             n/a              n/a
> openssl 095      0.9.5a-6.woody.6            n/a              n/a
> openssl 096           n/a               0.9.6m-1sarge1        n/a
> openssl 097           n/a                    n/a            0.9.7g-5

This is confusing - openssl 097 is marked as "n/a" for sarge, while in
fact the openssl package has version 0.9.7.  It is only logical if you
know the names of the source packages, but you shouldn't expect that
From every one reading that advisory.


> Debian GNU/Linux 3.0 alias woody
> --------------------------------

Furthermore, it would be great if these mails would state somewhere in
the actual text for which distributions an update is already available
(and possibly for which arches).  I read the mail cursory, decided that
I did not need to know the details, just upgrade, and was surprised that
aptitude had nothing to upgrade.  I had to read the mail again,
scrolling along the list of woody packages, to learn that there is
nothing but woody packages.

Thanks for considering,
Frank
-- 
Frank Küster
Inst. f. Biochemie der Univ. Zürich
Debian Developer

Attachment: pgpfOHH_IZAQH.pgp
Description: PGP signature


Reply to: