Bug#606995: Bug#606370: CVE-2010-2761 CVE-2010-4410 CVE-2010-4411

Niko Tyni ntyni at debian.org
Fri Jan 14 07:28:09 UTC 2011


On Thu, Jan 13, 2011 at 10:35:00PM +0000, Adam D. Barratt wrote:
> On Thu, 2011-01-13 at 22:55 +0100, gregor herrmann wrote:
> > I've now uploaded

> > - 3.38-2lenny2

> > I was a bit hesitant since I haven't seen a comment from the RT about
> > the uploads to lenny/squeeeze; but they can still decide now if they
> > accept the packages or not :)

> I've flagged the lenny package to be accepted at the next dinstall;
> thanks.

I thought stable would be fixed with a DSA, but as the next Lenny point
release will be out real soon (Jan 22nd, stable NEW freezes on the 17th),
I suppose that's just as good. Cc'ing the security team.

I'll try to get a perl lenny upload (#606995) in stable NEW by Monday.

That still leaves libcgi-simple-perl (#606379) unfixed. Is anybody looking at that?
-- 
Niko Tyni   ntyni at debian.org






More information about the Perl-maintainers mailing list