Hi Joey, Hans, has anyone actually tested this patch?
cheers, Holger As a sidenote and as you said you were new to packaging, Hans: I don't think it's wise to raise severity just because there is a patch or even because it's somehow privacy/security related: the latter is good in principle (but should be explained more specific/severe than just that), and the former, well, now we have a patch, but also a package removal if noone steps up and does the work. And this, while important bugs (and not only but especially security related ones) with straightforward changes can *always* be fixed, also in stable. So raising the severity just caused many people some attention unneededly. I do think the bug should be RC, I just think the reasoning given in https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774898#10 is wrong :-) justification: Even though it only affects some users, those are *silently* affected, and that's pretty serious IMHO.
signature.asc
Description: This is a digitally signed message part.