Bug#669196: libvorbisidec: multiple longstanding unfixed security issues in libvorbis

2013-01-17 Thread Daniel Kahn Gillmor
On 01/17/2013 06:42 AM, Jonathan Wiltshire wrote: > Package: libvorbisidec > Recently you fixed one or more security problems and as a result you closed > this bug. These problems were not serious enough for a Debian Security > Advisory, so they are now on my radar for fixing in the following suit

Bug#669196: libvorbisidec: multiple longstanding unfixed security issues in libvorbis

2013-01-17 Thread Jonathan Wiltshire
Package: libvorbisidec Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze (6.0

Bug#669196: libvorbisidec: multiple longstanding unfixed security issues in libvorbis

2012-04-17 Thread Michael Gilbert
package: libvorbisidec severity: grave version: 1.0.2+svn16259-2 tag: security libvorbisidec shares a large majority of its code with libvorbis. There have been quite a few security issues fixed in libvorbis over the past few years that have subsequently gone unfixed here. These include: CVE-200