Re: libapache2-mod-fcgid in lenny vulnerable to hole for weeks

2010-12-23 Thread Steve Kemp
On Tue Dec 21, 2010 at 22:21:35 +0100, Stefan Fritsch wrote: > FWIW, it seems the infrastructure has been finally fixed today, so I > hope things will improve now. But I do think that there are currently > to few active members in the security team. I am pretty sure we will > send out a request

Re: libapache2-mod-fcgid in lenny vulnerable to hole for weeks

2010-12-21 Thread Yves-Alexis Perez
(dropping the bug from CC:) On mar., 2010-12-21 at 22:21 +0100, Stefan Fritsch wrote: > FWIW, it seems the infrastructure has been finally fixed today, so I > hope things will improve now. But I do think that there are currently > to few active members in the security team. I am pretty sure we w

Re: libapache2-mod-fcgid in lenny vulnerable to hole for weeks

2010-12-21 Thread Stefan Fritsch
On Tuesday 21 December 2010, John Goerzen wrote: > I reported bug #605484 regarding a security hole in lenny. I > believe the security team was CC'd. > > Prior to my report, > http://security-tracker.debian.org/tracker/CVE-2010-3872 said that > Debian/stable was not vulnerable. I also notified t

libapache2-mod-fcgid in lenny vulnerable to hole for weeks

2010-12-21 Thread John Goerzen
Hi folks, I reported bug #605484 regarding a security hole in lenny. I believe the security team was CC'd. Prior to my report, http://security-tracker.debian.org/tracker/CVE-2010-3872 said that Debian/stable was not vulnerable. I also notified them to correct this issue. My question her