On Sun, Sep 30, 2007 at 01:54:12AM +0200, Nico Golde wrote:
> I intend to NMU this bug on behalf of the testing security 
> team.

Next time, please leave the maintainers more than 12 hours to respond
when you NMU for a bug that's open for less than three days. It also
helps to drop the maintainers a note before you start doing some work to
avoid duplication.

> I ported the patches to 6.2.4.5. The attached patch fixes 
> the 4 CVE ids.

Yes, and it break the package on 64bit archs, and introduces a new
security hole in the DCM coders. Nico, I appreciate your intent to help
with these bugs, but please don't blindly apply some random, unchecked
patches and call it a security upload. I'll fixup this mess with a
maintainer upload later on. It's currently test-building.

Daniel.




-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to