Bug#409703: sql-ledger in testing

2007-10-21 Thread Steffen Joeris
Hi Raphael I have read up on your discussion with the stable sec team. At the moment, sql-ledger is in testing and from what I have heard it would be possible to package and upload LedgerSMB, which fixes the security issues. Therefore, I would like to remove sql-ledger from testing. For lenny,

Bug#409703: sql-ledger in testing

2007-10-21 Thread Raphael Hertzog
Hi Steffen, On Sun, 21 Oct 2007, Steffen Joeris wrote: I have read up on your discussion with the stable sec team. At the moment, sql-ledger is in testing and from what I have heard it would be possible to package and upload LedgerSMB, which fixes the security issues. Therefore, I would

Bug#409703: sql-ledger in testing

2007-10-21 Thread Steffen Joeris
Hi Raphael On Sun, 21 Oct 2007 07:38:57 pm Raphael Hertzog wrote: Hi Steffen, On Sun, 21 Oct 2007, Steffen Joeris wrote: I have read up on your discussion with the stable sec team. At the moment, sql-ledger is in testing and from what I have heard it would be possible to package and

Bug#409703: sql-ledger in testing

2007-10-21 Thread Raphael Hertzog
Hi, On Sun, 21 Oct 2007, Steffen Joeris wrote: Also it won't be trivial to migrate from one to the other, so it's a fair bit of work to create the package and offer a sane upgrade path. We already documented the fact that sql-ledger is not safe to use in a untrusted environment. Well