On Dec/13, Uwe Kleine-König wrote: > Do you consider CVE-2016-6255 and CVE-2016-8863 bad enough to make a > security update for it? If so, I suggest the following debdiff.
Yes, the first one is bad, so let's fix both via a DSA. Could you please provide a debdiff with 1:1.6.19+git20141001-1+deb8u1 as a version, instead of 1.1 ? Cheers, --Seb