Bug#655960: security-tracker: DSA-2388-1 vs. tracker

2012-01-15 Thread Michael Gilbert
On Sun, Jan 15, 2012 at 7:42 AM, Yves-Alexis Perez wrote: > On dim., 2012-01-15 at 12:53 +0100, Francesco Poli (wintermute) wrote: >> Package: security-tracker >> Severity: normal >> >> Hi! >> >> The tracker page [1] for DSA-2388-1 [2] looks OK, but some of the >> referenced CVE tracker pages [3][

Bug#655960: security-tracker: DSA-2388-1 vs. tracker

2012-01-15 Thread Francesco Poli
On Sun, 15 Jan 2012 13:42:50 +0100 Yves-Alexis Perez wrote: > On dim., 2012-01-15 at 12:53 +0100, Francesco Poli (wintermute) wrote: [...] > > Assuming that the DSA is right and the tracker is wrong, please > > fix this inconsistency. [...] > > You're perfectly right, wheezy/sid doesn't have a fi

Bug#655960: security-tracker: DSA-2388-1 vs. tracker

2012-01-15 Thread Yves-Alexis Perez
On dim., 2012-01-15 at 12:53 +0100, Francesco Poli (wintermute) wrote: > Package: security-tracker > Severity: normal > > Hi! > > The tracker page [1] for DSA-2388-1 [2] looks OK, but some of the > referenced CVE tracker pages [3][4] claim that t1lib/5.1.2-3.3 is still > vulnerable in wheezy and

Bug#655960: security-tracker: DSA-2388-1 vs. tracker

2012-01-15 Thread Francesco Poli (wintermute)
Package: security-tracker Severity: normal Hi! The tracker page [1] for DSA-2388-1 [2] looks OK, but some of the referenced CVE tracker pages [3][4] claim that t1lib/5.1.2-3.3 is still vulnerable in wheezy and sid, while the DSA [2] claims that all the CVEs are fixed in wheezy and sid by t1lib/5.