Re: [SECURITY] [DSA 2360-1] Two month advance notification for upcoming end-of-life for Debian oldstable

2011-12-06 Thread Joerg Jaspert
On 12686 March 1977, Moritz Muehlenhoff wrote:


 Previously announced security updates for the old release will continue
 to be available on security.debian.org.

You might want to qualify this statement.

We will NOT have them there unlimited.
A few weeks or something after the last Lenny point release (which will
be sometime after the security stop) we will archive Lenny, which will
remove it from main, backports *and* security archive, going over to
archive.debian.org

-- 
bye, Joerg
ftpbot cron.daily time, unlocking: slave_NEW
mhy ftpbot: oh bugger off, slave_NEW isn't affected by dinstall :-)
tomv_w bugger off, sonst gibt es zoff!
tomv_w for the bilinguists


-- 
To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org
Archive: http://lists.debian.org/87sjkxl80k@gkar.ganneff.de



Re: [SECURITY] [DSA 2360-1] Two month advance notification for upcoming end-of-life for Debian oldstable

2011-12-06 Thread Andy Leake
ooops its actually Lenny!


On 7 December 2011 06:09, Moritz Muehlenhoff j...@debian.org wrote:

 -BEGIN PGP SIGNED MESSAGE-
 Hash: SHA1

 - -
 Debian Security Advisory DSA-2360-1   secur...@debian.org
 http://www.debian.org/security/Moritz Muehlenhoff
 December 6, 2011   http://www.debian.org/security/faq
 - -

 This is an advance notice that security support for Debian GNU/Linux 5.0
 (code name lenny) will be terminated in two months.

 The Debian project released Debian GNU/Linux 6.0 alias squeeze on the
 6th of February 2011. Users and distributors have been given a one-year
 timeframe to upgrade their old installations to the current stable
 release. Hence, the security support for the old release of 5.0 is going
 to end on the 6th of February 2012 as previously announced.

 Previously announced security updates for the old release will continue
 to be available on security.debian.org.

 Mailing list: debian-security-annou...@lists.debian.org
 -BEGIN PGP SIGNATURE-
 Version: GnuPG v1.4.11 (GNU/Linux)

 iEYEARECAAYFAk7edjgACgkQXm3vHE4uylqzdgCg5LIpBXVlN13c9QbZ/oX0Trrw
 lOkAoIAhSp72pvAD0dQ1IoTqIq3dW2X/
 =jC8t
 -END PGP SIGNATURE-


 --
 To UNSUBSCRIBE, email to debian-security-announce-requ...@lists.debian.org
 with a subject of unsubscribe. Trouble? Contact
 listmas...@lists.debian.org
 Archive:
 http://lists.debian.org/20111206200953.GA9595@pisco.westfalen.local




Bug#650929: security-tracker: DSA-2357-1 vs. tracker

2011-12-06 Thread Yves-Alexis Perez
On lun., 2011-12-05 at 18:47 +0100, Francesco Poli wrote:
  Yeah, and I don't know why, since in the source file the 3 CVEs are
  marked as fixed by 2.30.3-2.
 
 I am not sure: maybe because it's marked as fixed in (unstable) ?
 An additional entry for the stable fixed version is perhaps needed..

Yes, maybe, but I'd find that confusing :)
 .
 
   
   Please fix this last detail, if possible.
   Again, thanks for your time.
   
  I've requested some help for other team member, will keep you
 posted.
 
 Good, I hope it's not too tricky to get this thing right!
 
Hope too :)
-- 
Yves-Alexis


signature.asc
Description: This is a digitally signed message part