[Secure-testing-team] Question about the tracker

Francesco Poli frx at firenze.linux.it
Mon Jun 26 17:38:57 UTC 2006


Hi everyone again!  :)

There's something I cannot quite understand about
http://idssi.enyo.de/tracker/status/release/stable
On that status page there are two rows about mpg123:

mpg123 (non-free)	CVE-2006-1655		
	                DSA-1074-1

There first one refers to a vulnerability, while the second one refers
to the DSA that claims to fix that same vulnerability.
:-?
I thought that a vulnerability should disappear from the *stable* status
page, once it's fixed in security.debian.org...
At least, it seems that every other hole that was fixed in s.d.o and got
a DSA is not shown in the status page anymore.
Is this one special? Why?

-- 
    :-(   This Universe is buggy! Where's the Creator's BTS?   ;-)
......................................................................
  Francesco Poli                             GnuPG Key ID = DD6DFCF4
 Key fingerprint = C979 F34B 27CE 5CD8 DC12  31B5 78F4 279B DD6D FCF4
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://lists.alioth.debian.org/pipermail/secure-testing-team/attachments/20060626/8ceac1c1/attachment.pgp


More information about the Secure-testing-team mailing list