[pkg-fetchmail-maint] Re: fetchmail sec bug

Nico Golde nico at ngolde.de
Mon Aug 8 22:42:46 UTC 2005


Hi,
* Lucas Wall <lwall at debian.org> [2005-08-08 21:41]:
> Nico Golde wrote, On 08/08/05 15:27:
> > Hi,
> > #320357 is closed, what I had done wrong?
> > It should be open for stable.
> > Please help.
> 
> The bug is closed in unstable, but not in stable. Check:
> 
> http://bugs.debian.org/cgi-bin/pkgreport.cgi?pkg=fetchmail&dist=stable
> 
> Note the "dist=stable" at the end of the link. You can also see the
> "Found in versions ..." line at the top of the bug report.
> 
> Well... If you put "unstable" you will also see it open. Thats because
> hurd-i386 still has version 6.3.5-12.

Mhm yes but whats with the:
    * Will be archived: in 26 days. 
?

> When you ask for a particular distribution you will see the versions
> involved after the main title in the bug list page.
> 
> You can close a bug for a particular version using the command:
> 
> close <bug nbr> <version>
> 
> When a bug is closed with an upload the bug is closed for the version
> indicated in the changelog block it is in.

i know but why the website says it will be archived it isn't
closed?

> The sec team should eventually upload a new version for stable,
> something like 6.2.5-12.sarge1. The bug should then be closed for this
> particular version.

Yes, I mailed them.

> BTW... Did you hear anything else from the sec team? What exactly did
> you send them? Just the patch for fetchmail or did you prepare an upload
> for them?

I send them the patch not a whole package but they for shure
can use the package from unstable cause there is no upstream
version change.
I got one mail from Steve Kemp who asked for the patch and
then never heard anything about from them.
If I miss something, correct me but if not I think its a
shame to have an open security bug in sarge after some weeks. All other
distributions fixed it and it is easy to fix.
Regards Nico

-- 
Nico Golde - JAB: nion at jabber.ccc.de | GPG: 0x73647CFF
http://www.ngolde.de | http://www.muttng.org | http://grml.org 
VIM has two modes - the one in which it beeps 
and the one in which it doesn't -- encrypted mail preferred
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://lists.alioth.debian.org/pipermail/pkg-fetchmail-maint/attachments/20050809/fe2ac3ca/attachment-0001.pgp


More information about the pkg-fetchmail-maint mailing list