Hi Kurt, > I've uploaded 0.9.8o-4squeeze14 to squeeze-security
openssl/1.0.1e-1 changelog states the following: * New upstream version (Closes: #699889) - Fixes CVE-2013-0169, CVE-2012-2686, CVE-2013-0166 Meanwhile, openssl/0.9.8o-4squeeze14 changelog consist of the following line: * Fix CVE-2013-0166 and CVE-2013-0169 Thus, I have 2 questions: 1) is CVE-2012-2686 also fixed in openssl/0.9.8o-4squeeze14? 2) should bug#699889 be marked as fixed in openssl/0.9.8o-4squeeze14?