Bug#558355: lucene2: Please mention that CVE-2007-2383 has been fixed on next upload

2009-11-29 Thread Niels Thykier
Hi Jan-Pascal I believe this is what Torsten Werner did with jetty a few uploads back[1] and then passed -v to dpkg-genchanges/dpkg-buildpackage; but I am actually not sure if this is all there is too it. ~Niels [1] http://packages.qa.debian.org/j/jetty/news/20090906T213439Z.html

Bug#558355: lucene2: Please mention that CVE-2007-2383 has been fixed on next upload

2009-11-28 Thread Jan-Pascal van Best
Hi Niels, Would changing the changelog entry for lucene2 2.9.1+ds1-2 into lucene2 (2.9.1+ds1-2) unstable; urgency=low * Removed (unused) embedded Prototype javascript library (Closes: #555225, #555226; Fix CVE-2007-2383) do, on the next upload (which will be 2.9.1+ds1-3)? Cheers

Bug#558355: lucene2: Please mention that CVE-2007-2383 has been fixed on next upload

2009-11-27 Thread Niels Thykier
Package: lucene2 Severity: important Hi A recent upload of lucene2 fixed #555225; but did not mention that this fixed CVE-2007-2383. This causes the security tracker to believe that lucene2 is still affected. Therefore please mention that CVE-2007-2383 has been fixed in the changelog on next