Tags 481504 confirmed thanks Hi Steffen,
thanks for reporting this. I was wondering because you've written that 1.1.1 is vulnerable, which isn't in Debian, but it indeed affects 1.0.8 as well. I'm working on a package for 1.1.1 but as I'm waiting for upstream (they planned to make a bugfix release) an upload will not happen within the next few days. So I would appreciate a NMU. I haven't looked deeper in your patch, but it seems reasonable. I have forwarded it to the developers, because they are currently or has been working on this issue recently and I wanted to hear their opinion. Did you test your patch in a working install? Best Regards, -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]