-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, 9 Nov 2005 07:51:44 +0100
Martin Schulze <[EMAIL PROTECTED]> wrote:

> Steve Langasek wrote:
> > On Tue, Nov 08, 2005 at 10:15:26PM -0500, Charles Fry wrote:
> > 
> > > Version 6.4-1.1 of awstats was uploaded to unstable in response to
> > > CVE-2005-1527. However, it was never uploaded to stable-security,
> > > even though version 6.4.1 is the current stable version of
> > > awstats.
> > 
> > > As far as I can tell, 6.4-1.1 (or 6.4.2) should be uploaded to
> > > stable-security.
> > 
> > According to the changelog of 6.4-2, you are now a co-maintainer of
> > the awstats package.  Would you please prepare a 6.4-1sarge1 upload
> > to stable-security consisting of awstats 6.4-1 plus the security
> > patch?  If 6.4-1.1 doesn't contain any other changes that would be
> > inappropriate in a security update, 6.4-1sarge1 can be the same as
> > 6.4-1.1 with a different changelog.
> 
> A package that only consists of the security update as change would
> indeed be appreciated.  Please don't upload it to the regular queue,
> though

A package has now been uploaded to
ftp://security.debian.org/pub/SecurityUploadQueue

Hope it is correctly understood that when a firt-timer on
security-debian-org source needs to be incuded.


 - Jonas

- -- 
* Jonas Smedegaard - idealist og Internet-arkitekt
* Tlf.: +45 40843136  Website: http://dr.jones.dk/

 - Enden er nær: http://www.shibumi.org/eoti.htm
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFDcizLn7DbMsAkQLgRAhEYAJ9/vjlqpGk++mEy/ABAApkhk3TFjgCfXkrN
vvyv5dntbPiV/Qga+S+oIMo=
=PhHt
-----END PGP SIGNATURE-----

Reply via email to