Shouldn't we have at #656377 first? It seems to be a rather high impact security issue. And the patch fixing the problem is quite straightforward.
-- Regards, Aron Xu -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org