Bug#702115: libsocialweb/0.25.20-3.1

2013-03-25 Thread Jonathan Wiltshire
On Sat, Mar 02, 2013 at 08:57:02PM +, Jonathan Wiltshire wrote:
 Control: tag -1 + moreinfo
 
 On Sun, Mar 03, 2013 at 05:46:07AM +0900, Hideki Yamane wrote:
   libsocialweb package in testing has a security bug as CVE-2012-4511,
   and I've cherry-picked a patch from upstream as just 1 liner one.
  
   Please consider to unblock libsocialweb.
 
 The diff from testing to sid is not just your security fix:
 
 | Base version: libsocialweb_0.25.20-2 from testing
 | Target version: libsocialweb_0.25.20-3.1 from unstable
 
 If you want an isolated fix for the security issue it will have to go
 through t-p-u. I only glanced at the diff for sid, but it looks unsuitable
 at this stage (adding vala bindings, for example).

Ping?



-- 
Jonathan Wiltshire  j...@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC  74C3 5394 479D D352 4C51

directhex i have six years of solaris sysadmin experience, from
8-10. i am well qualified to say it is made from bonghits
layered on top of bonghits


signature.asc
Description: Digital signature


Bug#702115: libsocialweb/0.25.20-3.1

2013-03-02 Thread Hideki Yamane
Package: release.debian.org
Severity: normal
User: release.debian@packages.debian.org
Usertags: unblock

 libsocialweb package in testing has a security bug as CVE-2012-4511,
 and I've cherry-picked a patch from upstream as just 1 liner one.

 Please consider to unblock libsocialweb.


libsocialweb.debdiff
Description: Binary data


Bug#702115: libsocialweb/0.25.20-3.1

2013-03-02 Thread Jonathan Wiltshire
Control: tag -1 + moreinfo

On Sun, Mar 03, 2013 at 05:46:07AM +0900, Hideki Yamane wrote:
  libsocialweb package in testing has a security bug as CVE-2012-4511,
  and I've cherry-picked a patch from upstream as just 1 liner one.
 
  Please consider to unblock libsocialweb.

The diff from testing to sid is not just your security fix:

| Base version: libsocialweb_0.25.20-2 from testing
| Target version: libsocialweb_0.25.20-3.1 from unstable

If you want an isolated fix for the security issue it will have to go
through t-p-u. I only glanced at the diff for sid, but it looks unsuitable
at this stage (adding vala bindings, for example).

-- 
Jonathan Wiltshire  j...@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC  74C3 5394 479D D352 4C51

directhex i have six years of solaris sysadmin experience, from
8-10. i am well qualified to say it is made from bonghits
layered on top of bonghits


signature.asc
Description: Digital signature