On 2015-08-20 21:51:31, Salvatore Bonaccorso wrote:
> Source: vlc
> Version: 2.2.0~rc2-2
> Severity: grave
> Tags: security upstream patch fixed-upstream
> Justification: user security hole
> Control: fixed -1 2.2.0~rc2-2+deb8u1

Is this the way the Security Team works nowadays? No coordination with the
maintainers at all. We could have at least coordinated the fix for sid.

We were also trying to push 2.2.1 to jessie with other fixes for not CVE-worthy
crashes. Admittely, the pu request hasn't gotten a reply from the Release Team
in ages, but still …

Thanks for not coordinating with us.
-- 
Sebastian Ramacher

Attachment: signature.asc
Description: Digital signature

Reply via email to