On Fri, 23 Oct 2009 00:37:29 +0200 Richard Atterer wrote:

> On Thu, Oct 22, 2009 at 11:34:32PM +0200, Moritz Muehlenhoff wrote:
> > But please proceed with the removal from unstable by filing a removal bug 
> > against ftp.debian.org. Amaya has been removed and the other users have 
> > been fixed.
> 
> I've filed for removal: #552033
> 
> > Since CVE-2009-2625 doesn't allow code injection, but only DoS and given 
> > that libwww in oldstable is only used by wmweather, I think we can ignore 
> > it, unless Nico wants to work on an update?
> 
> Well, I've already prepared new versions of the packages, although they are 
> completely untested ATM, except that I had a look at them with 
> debdiff/interdiff: <http://atterer.net/libwww/>
> 
> Are you interested in using these?

this is being tracked as a minor issue, so you can get this pushed into
the next etch point release by filing a bug against release.debian.org.
a DSA will not be issued.

mike



-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to