Hi Michal, hi Luis On Mon, Apr 22, 2013 at 08:44:25PM +0200, Michal Trojnara wrote: > On 2013-04-22 20:02, Salvatore Bonaccorso wrote: > > Unfortunately stunnel4 package cannot be updated to latest upstream > > version due to the freeze and wheezy beeing relased very soon. So the > > version based on 4.53 needs to be patched. > I think the patch correctly addresses this specific security issue.
Thank you for confirming this. > On the other hand 4.53 is outdated and it lacks several important > stability bugfixes I implemented during the last year, e.g. half-close > handling, signal handling, memory leaks, file descriptor leaks, and > randoms stalls in libwrap support. I would really love 4.56 to make it > into wheezy, or *at least* into sid. It's a pity Debian users cannot > benefit from numerous hours of my work spent improving stunnel. > http://www.stunnel.org/sdf_ChangeLog.html Really understandable! Unfortunately it's really too late now to get this into wheezy (wheezy is planned to be released on 4th or 5th may, see, [1]). [1]: http://lists.debian.org/debian-devel-announce/2013/04/msg00006.html I suggest, that as soon wheezy is released the new upstream version can be packaged and uploaded to unstable. Luis? ;-) It is really appreciated that you reply also on downstream bugreports, thats great! Thank you very much for your quick followups. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org