> You did notice that the author claims the problems not to be exploitable, > right?
Yes, right before the original submitter claims that is it indeed exploitable. > Should be fixed anyway, but without further investigation it may > not require a CVE id or a DSA. > My understanding of the exploitable method is not enought to decide who is right, so I updated a new version to unstable which fix the problem and I leave to you, to decide if an update would be needed for stable or not. I can prepare such package if you want. Regards, Hector
signature.asc
Description: Esta parte del mensaje =?ISO-8859-1?Q?est=E1?= firmada digitalmente