On 08/10/2011 10:53 PM, Moritz Muehlenhoff wrote:
> On what basis did you come to that conclusion? Did you validate the
> upstream patches against the Squeeze version?
Whatever upstream had applied, part of it was overridden when we built
it. I fixed this in 1.2-4 with assistance from Steve Beattie. Squeeze
has 1.2-5


Timo: This was the bug I was talking about earlier. The CVEs were
CVE-2010-4170, CVE-2010-4171. And the upstream fix:
http://sources.redhat.com/git/gitweb.cgi?p=systemtap.git;a=commit;h=b7565b41228bea196cefa3a7d43ab67f8f9152e2
Debian Bug: #603946

-- 
Ritesh Raj Sarraf
RESEARCHUT - http://www.researchut.com
"Necessity is the mother of invention."

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to