Control: fixed -1 58.1-1 Hi,
On Fri, Nov 18, 2016 at 06:38:57PM +0100, László Böszörményi wrote: > Hi Salvatore, > > Thanks for the ping and the actual ICU bug link. > > On Fri, Nov 18, 2016 at 3:34 PM, Salvatore Bonaccorso <car...@debian.org> > wrote: > > According to https://bugzilla.redhat.com/show_bug.cgi?id=1377361#c5 > > there is now an upstream bug about the issue, but unfortunately for > > some reason it is still marked as private. > > > > http://bugs.icu-project.org/trac/ticket/12745 > That's for two weeks now! I don't see a reason why this vulnerability > takes such long to fix in ICU. :( Hopefully it will be open in time > for Stretch. :-/ According to upstream this has been fixed in 58.1 upstream. The bug is still not public, but this is as by https://sites.google.com/site/icusite/security . Regards, Salvatore