Re: [SECURITY] [DSA 2403-1] php5 security update
On Mon, February 6, 2012 03:24, Carlos Alberto Lopez Perez wrote:
> On 05/02/12 22:52, Luk Claes wrote:
>> On 02/05/2012 05:23 PM, Carlos Alberto Lopez Perez wrote:
>>> On 04/02/12 01:12, Luk Claes wrote:
>>>> On 02/03/2012 10:35 PM, Mario Antonio wrote:
>>>>> Do you think that there will be a fix for Lenny even though
>>>>> Lenny will be ending his life this weekend ?
>>>> It's already there in the archive, the DSA mail only still needs
>>>> to be sent.
>>> According to the security tracker is still unfixed . Also I am
>>> not able to find a 5.2.6.dfsg.1-1+lenny17 version on the
>>> repository... ???
>> The security tracker gets updated by sending the DSA mail...
> Perhaps it would be better to update when releasing the package? I don't
> know if this is easy to achieve, but from my limited point of view, at
> first sight looks a good idea since this would allow a better
> synchronization between the security tracker and the package status.
This happens in the ideal situation.
In practice circumstances forced me to make the decision to either: upload
the packages on friday and push the other changes later, or: postpone
upload + changes to monday. Given the seriousness of the issue I opted to
install the update as soon as possible.
The tracker has been updated since early this morning, and I'll send out
the email tonight.