[Bug 1776600] Re: version 3.3.1 has a security hole CVE-2017-11610

2018-06-22 Thread Marc Deslauriers
** Changed in: supervisor (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1776600 Title: version 3.3.1 has a security hole CVE-2017-11610 To manage

[Bug 1776600] Re: version 3.3.1 has a security hole CVE-2017-11610

2018-06-13 Thread Leonidas S. Barbosa
When a new release is made it take as base some debian release in that time with a bunch of aligned upstream packages is choice and all libraries are put together. What happens is that we freeze those versions to keep doing updates, such as security ones. Upstream packages don't freezes their

[Bug 1776600] Re: version 3.3.1 has a security hole CVE-2017-11610

2018-06-13 Thread Janusz Harkot
Thanks for the feedback. One more question from my side - why not to update to the newest supervisor instead of patching older version? I'm asking because it looks like there is always a lag on this package :) is there anything I can do to keep this package actual? -- You received this bug

[Bug 1776600] Re: version 3.3.1 has a security hole CVE-2017-11610

2018-06-13 Thread Leonidas S. Barbosa
Hi Janusz! Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to

[Bug 1776600] Re: version 3.3.1 has a security hole CVE-2017-11610

2018-06-13 Thread Leonidas S. Barbosa
Decided to keep this as public-security since it has CVE and sec update info. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1776600 Title: version 3.3.1 has a security hole CVE-2017-11610 To