Hi Martin, 

On Thu, Jul 06, 2006 at 01:05:15PM +0200, Martin Pitt wrote:
 
> There is a buffer overflow in st.c. Please see
> 
>   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2754
> 
> for links to more detailled descriptions and a pointer to the upstream
> CVS patch.
> 
> Please mention the CVE number in the changelog when you fix this.

How is the current procedure for security uploads (RTFM pointer is good
enough)? We can surely provide an updated package for sarge but I fear 
duplicated work with the security team. 

@Matthijs: I can build an updated sarge package by tomorrow I think, any
objections?

Greetings

        Torsten

Attachment: signature.asc
Description: Digital signature

Reply via email to