> You did notice that the author claims the problems not to be exploitable,
> right?

Yes, right before the original submitter claims that is it indeed
exploitable.

>   Should be fixed anyway, but without further investigation it may
> not require a CVE id or a DSA.
> 
My understanding of the exploitable method is not enought to decide who
is right, so I updated a new version to unstable which fix the problem
and I leave to you, to decide if an update would be needed for stable or
not.
I can prepare such package if you want.

Regards,

Hector

Attachment: signature.asc
Description: Esta parte del mensaje =?ISO-8859-1?Q?est=E1?= firmada digitalmente

Reply via email to