On 21-Aug-2009, Moritz Muehlenhoff wrote:
> This is indeed a security issue, but not important enough to warrant
> a DSA. However, we encourage maintainers to fix such minor security
> issues through a point update.

I have taken on the upstream maintainer role for this package, and am
currently testing a fix for this bug in a new version.

> To do so, please prepare an updated package for stable and send a
> debdiff to debian-rele...@lists.debian.org for review.

Back-porting the fix will not be impossible, but will be very tedious
because of many refactoring changes in the meantime. I guess, for
exacely the same reason, it's not acceptable to submit a package of
the new upstream version?

-- 
 \      “Life does not cease to be funny when people die any more than |
  `\  it ceases to be serious when people laugh.” —George Bernard Shaw |
_o__)                                                                  |
Ben Finney <b...@benfinney.id.au>

Attachment: signature.asc
Description: Digital signature

Reply via email to