Package: exif Severity: grave Tags: security CVE-2012-2845 (please see #681454 for the initial report) needs to be fixed in exif rather than libexif.
This doesn't warrant a DSA, but you could still fix it through a stable point update. Cheers, Moritz -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org