Re: DSA vs tracker: is CVE-2008-5814 fixed in unstable?

2009-05-11 Thread Thijs Kinkhorst
On moandei 11 Maaie 2009, Michael S. Gilbert wrote: security team, should the DSA announcement be reissued to correct/clarify? That should not be necessary. The DSA mails pertain to the state of afairs in old/stable; we mention sid fixed versions as a courtesy but I don't see it necessary to

Re: DSA vs tracker: is CVE-2008-5814 fixed in unstable?

2009-05-11 Thread Thijs Kinkhorst
On moandei 11 Maaie 2009, Michael S. Gilbert wrote: security team, should the DSA announcement be reissued to correct/clarify? That should not be necessary. The DSA mails pertain to the state of afairs in old/stable; we mention sid fixed versions as a courtesy but I don't see it necessary to

Re: DSA vs tracker: is CVE-2008-5814 fixed in unstable?

2009-05-10 Thread Michael S. Gilbert
On Sat, 9 May 2009 17:31:11 +0200 Francesco Poli wrote: Hi everyone! DSA-1789-1 [1] claims that all the mentioned CVEs are fixed in php5/5.2.9.dfsg.1-1 for sid. All tracker pages for the mentioned CVEs seem to be consistent, except for the one for CVE-2008-5814 [2], which claims that sid is

DSA vs tracker: is CVE-2008-5814 fixed in unstable?

2009-05-09 Thread Francesco Poli
Hi everyone! DSA-1789-1 [1] claims that all the mentioned CVEs are fixed in php5/5.2.9.dfsg.1-1 for sid. All tracker pages for the mentioned CVEs seem to be consistent, except for the one for CVE-2008-5814 [2], which claims that sid is still vulnerable. [1]