brian m. carlson | 17 Apr 2008 21:31

Re: acon package needs audit

On Thu, Apr 17, 2008 at 08:43:25PM +0200, أحمد المحمودي wrote:
>Hello,
>
>  I have been told on #debian-security that acon (a package that I 
>  maintian) needs audit.

Yes, it does.  I just found a security bug after looking for two 
minutes.

What's the standard procedure for a package that is in testing/unstable 
but not in stable?

--

-- 
brian m. carlson / brian with sandals: Houston, Texas, US
+1 713 440 7475 | http://crustytoothpaste.ath.cx/~bmc | My opinion only
troff on top of XML: http://crustytoothpaste.ath.cx/~bmc/code/thwack
OpenPGP: RSA v4 4096b 88AC E9B2 9196 305B A994 7552 F1BA 225C 0223 B187
Steve Kemp | 17 Apr 2008 21:59
Picon
Favicon
Gravatar

Re: acon package needs audit

On Thu Apr 17, 2008 at 19:31:40 +0000, brian m. carlson wrote:

>>  I have been told on #debian-security that acon (a package that I  
>> maintian) needs audit.
>
> Yes, it does.  I just found a security bug after looking for two  
> minutes.
>
> What's the standard procedure for a package that is in testing/unstable  
> but not in stable?

  Either report a bug to the maintainer, who will pass it on, or
 file a public bug in the BTS.

  The testing security team could also be an alternate person
 to contact.

  PS.  Good catch!

Steve
--

-- 
Managed Anti-Spam Service
http://mail-scanning.com/

Nico Golde | 17 Apr 2008 21:58
Picon
Favicon

Re: acon package needs audit

Hi,
* brian m. carlson <sandals <at> crustytoothpaste.ath.cx> [2008-04-17 21:40]:
> On Thu, Apr 17, 2008 at 08:43:25PM +0200, ???????? ???????????????? wrote:
> > I have been told on #debian-security that acon (a package that I  maintian) 
> >needs audit.
> 
> Yes, it does.  I just found a security bug after looking for two minutes.
> 
> What's the standard procedure for a package that is in testing/unstable but not 
> in stable?

File a bug if the version in unstable/testing is affected.
Cheers
Nico
--

-- 
Nico Golde - http://www.ngolde.de - nion <at> jabber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Gmane